geopy.Point and Point.fromstring() may take excessive CPU time when parsing long, malformed coordinate strings due to inefficient regular-expression behavior. The numeric Point constructor is not affected.
Geocoders' reverse methods called with string inputs exercise the vulnerable path.
Applications are affected when they pass attacker-controlled strings to these APIs without an appropriate length limit. Repeated requests may cause denial of service.
// patchesFixed in geopy 2.5.0 by rejecting overly long (over 256 characters) coordinate strings before parsing.
// workaroundsLimit coordinate strings to a reasonable maximum length, such as 256 characters, before passing them to geopy.
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
- Attack vector
- Local
- Attack complexity
- Low
- Privileges required
- None
- User interaction
- None
- Scope
- Unchanged
- Confidentiality
- None
- Integrity
- None
- Availability
- Low