pypi package report

Is geopy safe?

1 known vulnerability, worst severity MODERATE.

// reach

14 direct dependencies

4 carry known advisories, worst CRITICAL

23 packages depend on it

an advisory here reaches each of them

Create a free accountfor every dependency path, dependent and what to upgrade
// ai model usage

No published models are known to use this package.


cvss
0.0
medium

severity out of 10

epss
0.00%
low

chance of exploitation in 30 days, 9th percentile of all CVEs

xyz score
not scored

CyberXYZ composite out of 10

fig. 01 — GHSA-mhvh-fq92-pfmr, the advisory selected below

// 1 advisories

GHSA-mhvh-fq92-pfmr

MODERATECVE-2026-77387
// impact

geopy.Point and Point.fromstring() may take excessive CPU time when parsing long, malformed coordinate strings due to inefficient regular-expression behavior. The numeric Point constructor is not affected.

Geocoders' reverse methods called with string inputs exercise the vulnerable path.

Applications are affected when they pass attacker-controlled strings to these APIs without an appropriate length limit. Repeated requests may cause denial of service.

// patches

Fixed in geopy 2.5.0 by rejecting overly long (over 256 characters) coordinate strings before parsing.

// workarounds

Limit coordinate strings to a reasonable maximum length, such as 256 characters, before passing them to geopy.

// cvss v3.1 vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Attack vector
Local
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
Low

Checked 2026-10-04 at 01:12 UTC. The most recent advisory here was published 2026-10-02. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.