Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-15691 | Hugging Face Transformers Regular Expression Denial of Service |
Github GHSA |
GHSA-qq3j-4f4f-9583 | Hugging Face Transformers Regular Expression Denial of Service |
Wed, 21 May 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Huggingface
Huggingface transformers |
|
| CPEs | cpe:2.3:a:huggingface:transformers:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Huggingface
Huggingface transformers |
|
| Metrics |
cvssV3_1
|
Tue, 20 May 2025 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Mon, 19 May 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 19 May 2025 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability in the `preprocess_string()` function of the `transformers.testing_utils` module in huggingface/transformers version v4.48.3 allows for a Regular Expression Denial of Service (ReDoS) attack. The regular expression used to process code blocks in docstrings contains nested quantifiers, leading to exponential backtracking when processing input with a large number of newline characters. An attacker can exploit this by providing a specially crafted payload, causing high CPU usage and potential application downtime, effectively resulting in a Denial of Service (DoS) scenario. | |
| Title | Regular Expression Denial of Service (ReDoS) in huggingface/transformers | |
| Weaknesses | CWE-1333 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: @huntr_ai
Published:
Updated: 2025-05-19T13:45:13.385Z
Reserved: 2025-03-07T17:39:16.856Z
Link: CVE-2025-2099
Updated: 2025-05-19T13:39:29.149Z
Status : Analyzed
Published: 2025-05-19T12:15:19.640
Modified: 2025-05-21T17:43:15.080
Link: CVE-2025-2099
OpenCVE Enrichment
No data.
EUVD
Github GHSA