Hi, The following vulnerability was published for geopy. CVE-2026-77387[0]: | geopy is a geocoding library for Python. Prior to 2.5.0, geopy.Point | and Point.from_string() can spend excessive CPU time due to | inefficient regular-expression behavior when an application passes a | long malformed coordinate string without the 256-character input | limit used by the fix. Geocoder reverse methods also reach the | vulnerable parsing path when called with string inputs. Repeated | attacker-controlled requests can cause a denial of service, while | the numeric Point constructor is unaffected. This issue is fixed in | version 2.5.0. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-77387 https://www.cve.org/CVERecord?id=CVE-2026-77387 [1] https://github.com/geopy/geopy/security/advisories/GHSA-mhvh-fq92-pfmr [2] https://github.com/geopy/geopy/issues/608 [3] https://github.com/geopy/geopy/pull/610 [4] https://github.com/geopy/geopy/commit/5d09fa843f90ec80788b61552539c9fd3ae6c528 Regards, Salvatore