CVE-2026-77387
### Impact `geopy.Point` and `Point.from_string()` may take excessive CPU time when parsing long, malformed coordinate strings due to inefficient regular-expression behavior. The numeric Point constructor is not affected. Geocoders' `reverse` methods called with string inputs exercise the vulnerable path. Applications are affected when they pass attacker-controlled strings to these APIs without an appropriate length limit. Repeated requests may cause denial of service. ### Patches Fixed in geopy **2.5.0** by rejecting overly long (over 256 characters) coordinate strings before parsing. ### Workarounds Limit coordinate strings to a reasonable maximum length, such as 256 characters, before passing them to geopy.
Properties
- severity
- medium
- summary
- geopy: Regular Expression Denial of Service (ReDoS) in geopy.Point
- epss_score
- 0.00201
- cvss_score
- 4
- retrieved_at
- 2026-10-03T18:15:53+00:00
- ghsa_published
- 2026-10-02T22:38:14Z
- source_url
- https://github.com/advisories/GHSA-mhvh-fq92-pfmr
- ghsa_updated
- 2026-10-02T22:38:16Z
- ghsa_id
- GHSA-mhvh-fq92-pfmr
- last_source
- FIRST EPSS
- cve_id
- CVE-2026-77387
- cvss_vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
- signal_observed_at
- 2026-10-03T01:59:23+00:00
- is_ghsa_only
- false
- epss_percentile
- 0.09007
Related Entities (5)
ENRICHED_BY (1)
REPORTED_BY (1)
VULNERABLE_TO (1)
AFFECTS (1)
HAS_WEAKNESS (1)
Explore deeper with Ninja Signal's threat intelligence graph