geopy.Point and Point.from_string() may take excessive CPU time when parsing long, malformed coordinate strings due to inefficient regular-expression behavior. The numeric Point constructor is not affected.
Geocoders' reverse methods called with string inputs exercise the vulnerable path.
Applications are affected when they pass attacker-controlled strings to these APIs without an appropriate length limit. Repeated requests may cause denial of service.
Fixed in geopy 2.5.0 by rejecting overly long (over 256 characters) coordinate strings before parsing.
Limit coordinate strings to a reasonable maximum length, such as 256 characters, before passing them to geopy.
{
"cwe_ids": [
"CWE-1333"
],
"github_reviewed": true,
"github_reviewed_at": "2026-10-02T22:38:14Z",
"nvd_published_at": "2026-10-01T17:17:31Z",
"severity": "MODERATE"
}