CVE-2026-77387

NameCVE-2026-77387
Descriptiongeopy is a geocoding library for Python. Prior to 2.5.0, geopy.Point a ...
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
geopy (PTS)bookworm2.3.0-1vulnerable
trixie2.4.1-1vulnerable
forky, sid2.4.1-3vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
geopysource(unstable)(unfixed)

Notes

https://github.com/geopy/geopy/security/advisories/GHSA-mhvh-fq92-pfmr
https://github.com/geopy/geopy/issues/608
https://github.com/geopy/geopy/pull/610
Fixed by: https://github.com/geopy/geopy/commit/5d09fa843f90ec80788b61552539c9fd3ae6c528 (2.5.0)

Search for package or bug name: Reporting problems