← العودة للجدول
CVE-2026-77387
CVE-2026-77387 — geopy: Regular Expression Denial of Service (ReDoS) in geopy.Point
📅 2026-10-03
🟡 Medium 🔥 No GHSA Vulnerability Vulnerability CVSS 4

📋 الوصف الكامل

### Impact `geopy.Point` and `Point.from_string()` may take excessive CPU time when parsing long, malformed coordinate strings due to inefficient regular-expression behavior. The numeric Point constructor is not affected. Geocoders' `reverse` methods called with string inputs exercise the vulnerable path. Applications are affected when they pass attacker-controlled strings to these APIs wi

💻 الأنظمة المتأثرة

⚠️ نوع التهديد

Vulnerability

🔗 CVE ID

CVE-2026-77387

📡 المصدر

GHSA

✅ الحلول والتخفيف

Update to v2.5.0

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ← 🔍 Valters IT ←