CVE-2026-77387: geopy: Regular Expression Denial of Service (ReDoS) in geopy.Point

Published Oct 1, 2026
·
Updated

geopy is a geocoding library for Python. Prior to 2.5.0, geopy.Point and Point.fromstring() can spend excessive CPU time due to inefficient regular-expression behavior when an application passes a long malformed coordinate string without the 256-character input limit used by the fix. Geocoder reverse methods also reach the vulnerable parsing path when called with string inputs. Repeated attacker-controlled requests can cause a denial of service, while the numeric Point constructor is unaffected. This issue is fixed in version 2.5.0.

Affected Software

1 affected component
pypi/geopy<2.5.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade geopy to a version that resolves this vulnerability.

    Fixed in 2.5.0

Event History

Oct 1, 2026
CVE Published
via MITRE·04:38 PM
Data Sourced
via MITRE·04:38 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which application paths are exposed to this issue?

Applications are exposed when they pass long, malformed attacker-controlled coordinate strings to geopy.Point, Point.from_string(), or geocoder reverse methods that accept string inputs. The numeric Point constructor is unaffected.

2

Does exploitation require authentication or user interaction?

No. The supplied vector indicates that exploitation requires neither privileges nor user interaction, but the vulnerable parsing path must receive a malicious string.

3

Are default deployments affected?

The provided information does not establish whether any particular application default configuration passes untrusted strings into these APIs. Exposure depends on how the application accepts and forwards coordinate input.

4

What can be done before upgrading?

Enforce a maximum length of 256 characters for coordinate strings before passing them to the affected geopy parsing paths, and reject malformed or unexpectedly long input. Upgrading to geopy 2.5.0 fixes the issue.

5

How can teams identify likely exposure?

Review code paths that use Point, Point.from_string(), or geocoder reverse methods with string inputs, especially where coordinates originate from requests or other untrusted sources. Deployments using only the numeric Point constructor are not affected by this issue.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203