GHSA-mhvh-fq92-pfmr: Medium severity pip/geopy vulnerability
Impact
geopy.Point and Point.fromstring() may take excessive CPU time when parsing long, malformed coordinate strings due to inefficient regular-expression behavior. The numeric Point constructor is not affected.
Geocoders' reverse methods called with string inputs exercise the vulnerable path.
Applications are affected when they pass attacker-controlled strings to these APIs without an appropriate length limit. Repeated requests may cause denial of service.
Patches
Fixed in geopy 2.5.0 by rejecting overly long (over 256 characters) coordinate strings before parsing.
Workarounds
Limit coordinate strings to a reasonable maximum length, such as 256 characters, before passing them to geopy.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/geopyto a version that resolves this vulnerability.Fixed in 2.5.0 - Upgrade
Upgrade
geopyto a version that resolves this vulnerability.Fixed in 2.5.0 - Compensating control
Limit coordinate strings to a maximum of 256 characters before passing them to geopy, especially for geocoders' reverse methods and geopy.Point.from_string().
Event History
Frequently Asked Questions
Which uses of geopy are exposed to this denial-of-service issue?
Applications are affected when attacker-controlled coordinate strings are passed to geopy.Point, Point.from_string(), or geocoder reverse methods that receive string inputs. The numeric Point constructor is not affected.
What does an attacker need to do to exploit the issue?
An attacker needs to supply a long, malformed coordinate string to a vulnerable parsing path. Repeated requests using such inputs may consume excessive CPU time and cause denial of service.
Are default deployments affected?
Exposure depends on application behavior rather than a stated default configuration. An application is affected if it accepts attacker-controlled coordinate strings and does not enforce an appropriate length limit before passing them to the affected APIs.
What can be done if upgrading is not immediately possible?
Reject or limit coordinate strings before they reach geopy, using a maximum length such as 256 characters. This prevents overly long inputs from reaching the inefficient parser.
How can I remediate the issue permanently?
Upgrade geopy to version 2.5.0 or later. This version rejects coordinate strings longer than 256 characters before parsing.