CVE-2026-77387
Received Received - Intake

Denial of Service in geopy via Malformed Coordinate Strings

Vulnerability report for CVE-2026-77387, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: GitHub, Inc.

Description

geopy is a geocoding library for Python. Prior to 2.5.0, geopy.Point and Point.from_string() can spend excessive CPU time due to inefficient regular-expression behavior when an application passes a long malformed coordinate string without the 256-character input limit used by the fix. Geocoder reverse methods also reach the vulnerable parsing path when called with string inputs. Repeated attacker-controlled requests can cause a denial of service, while the numeric Point constructor is unaffected. This issue is fixed in version 2.5.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
geopy geopy 2.5.0
geopy geopy to 2.5.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1333 The product uses a regular expression with an inefficient, possibly exponential worst-case computational complexity that consumes excessive CPU cycles.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Regular Expression Denial of Service (ReDoS) vulnerability in the geopy library affecting versions up to 2.4.1. It occurs in the geopy.Point class and Point.from_string() method when parsing long, malformed coordinate strings. The issue is caused by inefficient regular expression handling that leads to excessive CPU time consumption due to catastrophic backtracking.

Detection Guidance

To detect this vulnerability, monitor CPU usage spikes when processing coordinate strings. Check if geopy.Point or Point.from_string() is called with long malformed inputs. Use logging to track requests exceeding 256 characters in coordinate strings.

Impact Analysis

An attacker could send repeated requests with long malformed coordinate strings to cause high CPU usage, leading to service disruption or denial of service. Applications using geopy.Point() or geocoder reverse methods with user-supplied location data are at risk. The numeric Point constructor is unaffected.

Compliance Impact

This vulnerability primarily causes denial of service through excessive CPU usage during regex processing of malformed inputs. While it does not directly violate GDPR or HIPAA, it could indirectly impact compliance by disrupting services that handle personal data. For example, a DoS condition might prevent timely access to health records (HIPAA) or user data (GDPR), potentially leading to violations if service levels are not maintained.

Mitigation Strategies
  • Upgrade geopy to version 2.5.0 or later to apply the fix.
  • Implement input validation to limit coordinate strings to 256 characters before processing.
  • Monitor network traffic for repeated requests with long malformed coordinate strings.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-77387. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart