
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-77387 is a Regular Expression Denial of Service (ReDoS) vulnerability in the geopy Python geocoding library affecting all versions up to and including 2.4.1. The flaw exists in geopy.Point and Point.from_string(), which can consume excessive CPU time when processing long, malformed coordinate strings due to catastrophic backtracking in the POINT_PATTERN regular expression. Geocoder reverse methods called with string inputs also reach the vulnerable code path. The vulnerability was reported on June 30, 2026, patched on July 10, 2026, and the security advisory was published July 12, 2026. It carries a CVSS v3.1 base score of 4.0 (Medium) (GitHub Advisory).
The root cause is classified as CWE-1333 (Inefficient Regular Expression Complexity). The POINT_PATTERN regex in geopy/point.py begins with .*? (to allow coordinates embedded after leading text) and matches whitespace in several overlapping places, creating overlapping quantifiers that trigger quadratic backtracking on adversarial inputs. An attacker-supplied string such as '<' + ' ' * 3000 + 'X' — a leading non-word character followed by thousands of spaces and a non-matching terminator — causes the regex engine to backtrack extensively, consuming approximately 206ms per request compared to ~0.01ms for a normal input. The numeric Point constructor is unaffected; only the string-parsing path via Point.__init__() and Point.from_string() is vulnerable (GitHub Issue, GitHub Advisory).
Successful exploitation causes a denial of service against any web application that passes user-controlled strings to geopy.Point() or Point.from_string() without input length validation. Each adversarial request blocks a server thread for approximately 200ms, and 100 concurrent malicious requests can exhaust a thread pool for roughly 20 seconds, rendering the service unresponsive to legitimate users. There is no confidentiality or integrity impact; the vulnerability is limited to availability (GitHub Issue, GitHub Advisory).
A proof-of-concept Python script demonstrating the timing difference between normal and adversarial inputs is publicly available in the GitHub issue report (GitHub Issue). The EPSS score is 0.0, and there is no evidence of in-the-wild exploitation or inclusion in the CISA KEV catalog. No authentication is required to exploit the vulnerability, but the target application must accept user-supplied coordinate strings and pass them directly to the vulnerable API without length validation. The NVD SSVC assessment classifies exploitation status as "poc" and automatable as "no" (Feedly).
GET /api/nearby?location=...), as geopy has approximately 2 million monthly PyPI downloads.adversarial = '<' + ' ' * 3000 + 'X'. URL-encoded form: location=%3C%20%20%20...%20X.GET /api/nearby?location=%3C%20%20%20...%20X. The application passes the string to geopy.Point(location) as per standard usage.POINT_PATTERN regex in geopy/point.py enters quadratic backtracking on the input, blocking the server thread for approximately 200ms per request./api/nearby, /api/geocode) with unusually long query parameter values (>256 characters) containing leading special characters (<, >) followed by large amounts of whitespace.%3C (less-than sign) followed by many %20 (space) sequences; elevated request latency or timeout errors on geocoding endpoints.Upgrade geopy to version 2.5.0 or later, which fixes the issue by rejecting any coordinate string longer than 256 characters before applying the regex, raising a ValueError for oversized inputs (geopy Release, Fix Commit). As a workaround for applications that cannot immediately upgrade, enforce a maximum length limit (e.g., 256 characters) on coordinate strings before passing them to geopy.Point() or Point.from_string(), and optionally apply a character class pre-check to reject strings containing unexpected characters. Additionally, implement rate limiting on geocoding API endpoints to reduce the impact of repeated malicious requests (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."