Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 01 Oct 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 01 Oct 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | geopy is a geocoding library for Python. Prior to 2.5.0, geopy.Point and Point.from_string() can spend excessive CPU time due to inefficient regular-expression behavior when an application passes a long malformed coordinate string without the 256-character input limit used by the fix. Geocoder reverse methods also reach the vulnerable parsing path when called with string inputs. Repeated attacker-controlled requests can cause a denial of service, while the numeric Point constructor is unaffected. This issue is fixed in version 2.5.0. | |
| Title | geopy: Regular Expression Denial of Service (ReDoS) in geopy.Point | |
| Weaknesses | CWE-1333 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-01T17:50:39.404Z
Reserved: 2026-08-20T19:36:13.806Z
Link: CVE-2026-77387
Updated: 2026-10-01T17:49:11.518Z
Status : Received
Published: 2026-10-01T17:17:31.733
Modified: 2026-10-01T18:17:27.723
Link: CVE-2026-77387
No data.
OpenCVE Enrichment
No data.
-
CWE-1333
Inefficient Regular Expression Complexity