CVE-2026-77387Medium· 4.0▾ TwilightPoC availablegeopy is a geocoding library for Python. Prior to 2.5.0, geopy.Point and Point.from_string() can spend excessive CPU time due to inefficient regular-expression behavior when an application passes a long malformed coordinate string withou…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 22 · likelihood 0 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
geopy is a geocoding library for Python. Prior to 2.5.0, geopy.Point and Point.from_string() can spend excessive CPU time due to inefficient regular-expression behavior when an application passes a long malformed coordinate string without the 256-character input limit used by the fix. Geocoder reverse methods also reach the vulnerable parsing path when called with string inputs. Repeated attacker-controlled requests can cause a denial of service, while the numeric Point constructor is unaffected. This issue is fixed in version 2.5.0.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2024-21490High· 7.5This affects versions of the package angular from 1.3.0; versions of the package angularjs from 1.3.0
CVE-2026-102990High· 8.2basic-ftp is an FTP client for Node.js
CVE-2026-103043High· 7.5anchorme through 3.0.8 contains a regular expression denial of service vulnerability in the IPv6 host extraction regex due to catastrophic backtracking
CVE-2026-102270Medium· 4.4PyJWT is a Python implementation of JSON Web Token standards
CVE-2026-101906High· 8.2Axios is a promise-based HTTP client for the browser and Node.js
CVE-2026-101903High· 8.2Axios is a promise-based HTTP client for the browser and Node.js