GHSA-mhvh-fq92-pfmr: Medium severity pip/geopy vulnerability

Published Oct 2, 2026
·
Updated

Impact

geopy.Point and Point.fromstring() may take excessive CPU time when parsing long, malformed coordinate strings due to inefficient regular-expression behavior. The numeric Point constructor is not affected.

Geocoders' reverse methods called with string inputs exercise the vulnerable path.

Applications are affected when they pass attacker-controlled strings to these APIs without an appropriate length limit. Repeated requests may cause denial of service.

Patches

Fixed in geopy 2.5.0 by rejecting overly long (over 256 characters) coordinate strings before parsing.

Workarounds

Limit coordinate strings to a reasonable maximum length, such as 256 characters, before passing them to geopy.

Affected Software

1 affected componentFixes available
pip/geopy<=2.4.1
2.5.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade pip/geopy to a version that resolves this vulnerability.

    Fixed in 2.5.0
  2. Upgrade

    Upgrade geopy to a version that resolves this vulnerability.

    Fixed in 2.5.0
  3. Compensating control

    Limit coordinate strings to a maximum of 256 characters before passing them to geopy, especially for geocoders' reverse methods and geopy.Point.from_string().

Event History

Oct 2, 2026
Advisory Published
via GitHub·10:38 PM
Data Sourced
via GitHub·10:38 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Which uses of geopy are exposed to this denial-of-service issue?

Applications are affected when attacker-controlled coordinate strings are passed to geopy.Point, Point.from_string(), or geocoder reverse methods that receive string inputs. The numeric Point constructor is not affected.

2

What does an attacker need to do to exploit the issue?

An attacker needs to supply a long, malformed coordinate string to a vulnerable parsing path. Repeated requests using such inputs may consume excessive CPU time and cause denial of service.

3

Are default deployments affected?

Exposure depends on application behavior rather than a stated default configuration. An application is affected if it accepts attacker-controlled coordinate strings and does not enforce an appropriate length limit before passing them to the affected APIs.

4

What can be done if upgrading is not immediately possible?

Reject or limit coordinate strings before they reach geopy, using a maximum length such as 256 characters. This prevents overly long inputs from reaching the inefficient parser.

5

How can I remediate the issue permanently?

Upgrade geopy to version 2.5.0 or later. This version rejects coordinate strings longer than 256 characters before parsing.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203