GHSA-mhvh-fq92-pfmrMediumCVSS 4.0

geopy: Regular Expression Denial of Service (ReDoS) in geopy.Point

Published
October 2, 2026
Last Modified
October 2, 2026

🔗 CVE IDs covered (1)

📋 Description

Impact

geopy.Point and Point.from_string() may take excessive CPU time when parsing long, malformed coordinate strings due to inefficient regular-expression behavior. The numeric Point constructor is not affected.

Geocoders' reverse methods called with string inputs exercise the vulnerable path.

Applications are affected when they pass attacker-controlled strings to these APIs without an appropriate length limit. Repeated requests may cause denial of service.

Patches

Fixed in geopy 2.5.0 by rejecting overly long (over 256 characters) coordinate strings before parsing.

Workarounds

Limit coordinate strings to a reasonable maximum length, such as 256 characters, before passing them to geopy.

🎯 Affected products1

  • pip/geopy:<= 2.4.1

🔗 References (7)