Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-77387— geopy: Regular Expression Denial of Service (ReDoS) in geopy.Point

Quick assessment

Affected
geopy geopy
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

geopy 是一个用于 Python 的地理编码库。在 2.5.0 版本之前,当应用程序传入一个长度超过修复措施中设定的 256 字符输入限制的错误坐标字符串时, 和 会因低效的正则表达式行为而消耗过多的 CPU 时间。此外,当以字符串作为输入调用 Geocoder 的反向地理编码方法时,也会触发存在漏洞的解析路径。攻击者通过重复发送受其控制的请求,可能导致拒绝服务(DoS)攻击;而使用数值参数调用 Point 构造函数则不受此问题影响。该漏洞已在 2.5.0 版本中修复。

CVSS 4.0 · Medium

Possible ATT&CK Techniques 1 AI

T1499 · Endpoint Denial of Service
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-77387

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
geopy: Regular Expression Denial of Service (ReDoS) in geopy.Point
Source: CVE Program / CVE List V5
Vulnerability Description
geopy is a geocoding library for Python. Prior to 2.5.0, geopy.Point and Point.from_string() can spend excessive CPU time due to inefficient regular-expression behavior when an application passes a long malformed coordinate string without the 256-character input limit used by the fix. Geocoder reverse methods also reach the vulnerable parsing path when called with string inputs. Repeated attacker-controlled requests can cause a denial of service, while the numeric Point constructor is unaffected. This issue is fixed in version 2.5.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
CWE-1333
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
geopy geopy < 2.5.0 -

II. Public POCs for CVE-2026-77387

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-77387

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-77387 (3)

Vendor Advisories for CVE-2026-77387 (1)

Vendor Pages for CVE-2026-77387 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-77387

No comments yet


Leave a comment