PT-2026-105530 · Pypi · Geopy

Published

2026-10-02

·

Updated

2026-10-02

CVSS v3.1

4.0

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Impact

geopy.Point and Point.from string() may take excessive CPU time when parsing long, malformed coordinate strings due to inefficient regular-expression behavior. The numeric Point constructor is not affected.
Geocoders' reverse methods called with string inputs exercise the vulnerable path.
Applications are affected when they pass attacker-controlled strings to these APIs without an appropriate length limit. Repeated requests may cause denial of service.

Patches

Fixed in geopy 2.5.0 by rejecting overly long (over 256 characters) coordinate strings before parsing.

Workarounds

Limit coordinate strings to a reasonable maximum length, such as 256 characters, before passing them to geopy.

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-MHVH-FQ92-PFMR

Affected Products

Geopy