CVE-2026-77387: geopy: Regular Expression Denial of Service (ReDoS) in geopy.Point
geopy is a geocoding library for Python. Prior to 2.5.0, geopy.Point and Point.fromstring() can spend excessive CPU time due to inefficient regular-expression behavior when an application passes a long malformed coordinate string without the 256-character input limit used by the fix. Geocoder reverse methods also reach the vulnerable parsing path when called with string inputs. Repeated attacker-controlled requests can cause a denial of service, while the numeric Point constructor is unaffected. This issue is fixed in version 2.5.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
geopyto a version that resolves this vulnerability.Fixed in 2.5.0
Event History
Frequently Asked Questions
Which application paths are exposed to this issue?
Applications are exposed when they pass long, malformed attacker-controlled coordinate strings to geopy.Point, Point.from_string(), or geocoder reverse methods that accept string inputs. The numeric Point constructor is unaffected.
Does exploitation require authentication or user interaction?
No. The supplied vector indicates that exploitation requires neither privileges nor user interaction, but the vulnerable parsing path must receive a malicious string.
Are default deployments affected?
The provided information does not establish whether any particular application default configuration passes untrusted strings into these APIs. Exposure depends on how the application accepts and forwards coordinate input.
What can be done before upgrading?
Enforce a maximum length of 256 characters for coordinate strings before passing them to the affected geopy parsing paths, and reject malformed or unexpectedly long input. Upgrading to geopy 2.5.0 fixes the issue.
How can teams identify likely exposure?
Review code paths that use Point, Point.from_string(), or geocoder reverse methods with string inputs, especially where coordinates originate from requests or other untrusted sources. Deployments using only the numeric Point constructor are not affected by this issue.