GHSA-mhvh-fq92-pfmr

Suggest an improvement
Source
https://github.com/advisories/GHSA-mhvh-fq92-pfmr
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-mhvh-fq92-pfmr/GHSA-mhvh-fq92-pfmr.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-mhvh-fq92-pfmr
Aliases
Downstream
CGA (12)
Published
2026-10-02T22:38:14Z
Modified
2026-10-02T22:45:03Z
Severity
  • 4.0 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L CVSS Calculator
Summary
geopy: Regular Expression Denial of Service (ReDoS) in geopy.Point
Details

Impact

geopy.Point and Point.from_string() may take excessive CPU time when parsing long, malformed coordinate strings due to inefficient regular-expression behavior. The numeric Point constructor is not affected.

Geocoders' reverse methods called with string inputs exercise the vulnerable path.

Applications are affected when they pass attacker-controlled strings to these APIs without an appropriate length limit. Repeated requests may cause denial of service.

Patches

Fixed in geopy 2.5.0 by rejecting overly long (over 256 characters) coordinate strings before parsing.

Workarounds

Limit coordinate strings to a reasonable maximum length, such as 256 characters, before passing them to geopy.

Database specific
{
    "cwe_ids": [
        "CWE-1333"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-10-02T22:38:14Z",
    "nvd_published_at": "2026-10-01T17:17:31Z",
    "severity": "MODERATE"
}
References

Affected packages

PyPI / geopy

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.5.0

Affected versions

0.*
0.92
0.93
0.94
0.94.1
0.94.2
0.95
0.95.1
0.96.0
0.96.1
0.96.2
0.96.3
0.97
0.97.1
0.98
0.98.1
0.98.2
0.98.3
0.99
1.*
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.9.0
1.9.1
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.18.1
1.19.0
1.20.0
1.21.0
1.22.0
1.23.0
2.*
2.0.0rc1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.4.1

Database specific

last_known_affected_version_range
"<= 2.4.1"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-mhvh-fq92-pfmr/GHSA-mhvh-fq92-pfmr.json"