mediumCVSS 4Vulnerability

CVE-2026-77387

### Impact `geopy.Point` and `Point.from_string()` may take excessive CPU time when parsing long, malformed coordinate strings due to inefficient regular-expression behavior. The numeric Point constructor is not affected. Geocoders' `reverse` methods called with string inputs exercise the vulnerable path. Applications are affected when they pass attacker-controlled strings to these APIs without an appropriate length limit. Repeated requests may cause denial of service. ### Patches Fixed in geopy **2.5.0** by rejecting overly long (over 256 characters) coordinate strings before parsing. ### Workarounds Limit coordinate strings to a reasonable maximum length, such as 256 characters, before passing them to geopy.

Properties

severity
medium
summary
geopy: Regular Expression Denial of Service (ReDoS) in geopy.Point
epss_score
0.00201
cvss_score
4
retrieved_at
2026-10-03T18:15:53+00:00
ghsa_published
2026-10-02T22:38:14Z
source_url
https://github.com/advisories/GHSA-mhvh-fq92-pfmr
ghsa_updated
2026-10-02T22:38:16Z
ghsa_id
GHSA-mhvh-fq92-pfmr
last_source
FIRST EPSS
cve_id
CVE-2026-77387
cvss_vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
signal_observed_at
2026-10-03T01:59:23+00:00
is_ghsa_only
false
epss_percentile
0.09007

Related Entities (5)

ENRICHED_BY (1)

→[Source]FIRST EPSS

REPORTED_BY (1)

→[Source]GitHub Advisory Database

VULNERABLE_TO (1)

←[Software]pip/geopy

AFFECTS (1)

→[Software]pip/geopy

HAS_WEAKNESS (1)

→[Weakness]Inefficient Regular Expression Complexity

Explore deeper with Ninja Signal's threat intelligence graph