Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-52852— Traccar: Uncontrolled Infinite Loop DoS via Group Parent Cycle

Quick assessment

Affected
traccar traccar
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Traccar 是一个开源的 GPS 追踪系统。在 6.14.0 版本之前,具有管理组和请求报告权限的已认证用户可以创建一个循环的“组-父级”层级结构,并为该层级中的设备请求行程或停靠点报告。 允许父级循环,而 在遍历组父级时,既没有循环检测,也没有使用访问集合(visited set)或深度限制。 通过 和 触发的基于存储的后端查找过程永远不会终止;当客户端断开连接后,仍会占用一个 Jetty 工作线程并持续高 CPU 使用。若此类请求被重复发起,可能导致 Web/API 工作线程池耗尽。基于位置摄取缓存的查找路

CVSS 6.5 · Medium EPSS 0.03% · P10

Possible ATT&CK Techniques 2 AI

T1235 T1499 · Endpoint Denial of Service

Affected Version Matrix 1

VendorProduct Version RangeStatus
traccar traccar < 6.14.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-52852

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Traccar: Uncontrolled Infinite Loop DoS via Group Parent Cycle
Source: CVE Program / CVE List V5
Vulnerability Description
Traccar is an open source GPS tracking system. Prior to 6.14.0, an authenticated user with permission to manage groups and request reports can create a cyclic group-parent hierarchy and request a trips or stops report for a device in that hierarchy. org.traccar.api.resource.GroupResource permits the parent cycle, while org.traccar.helper.model.AttributeUtil.lookup follows group parents without cycle detection, a visited set, or a depth limit. The storage-backed lookup reached through TripsConfig. and ReportUtils.slowTripsAndStops never terminates, pins a Jetty worker at high CPU after the client disconnects, and can exhaust the web/API worker pool when requests are repeated. The position-ingestion cache-backed path is not part of the confirmed affected scope. This issue is fixed in 6.14.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
未经控制的递归
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
traccar traccar < 6.14.0 -

II. Public POCs for CVE-2026-52852

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-52852

登录查看更多情报信息。

Patches & Fixes for CVE-2026-52852 (1)

Vendor Advisories for CVE-2026-52852 (1)

Vendor Pages for CVE-2026-52852 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-52852

No comments yet


Leave a comment