Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-27083 | xgrammar is an open-source library for efficient, flexible, and portable structured generation. A grammar optimizer introduced in 0.1.23 processes large grammars (>100k characters) at very low rates, and can be used for DOS of model providers. This issue is fixed in version 0.1.24. |
Github GHSA |
GHSA-9q5r-wfvf-rr7f | xgrammar vulnerable to denial of service by huge enum grammar |
Thu, 18 Sep 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:mlc-ai:xgrammar:0.1.23:*:*:*:*:*:*:* |
Mon, 15 Sep 2025 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Mon, 08 Sep 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 08 Sep 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mlc-ai
Mlc-ai xgrammar |
|
| Vendors & Products |
Mlc-ai
Mlc-ai xgrammar |
Sat, 06 Sep 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | xgrammar is an open-source library for efficient, flexible, and portable structured generation. A grammar optimizer introduced in 0.1.23 processes large grammars (>100k characters) at very low rates, and can be used for DOS of model providers. This issue is fixed in version 0.1.24. | |
| Title | xgrammar vulnerable to denial of service by huge enum grammar | |
| Weaknesses | CWE-770 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-09-08T17:55:13.537Z
Reserved: 2025-09-01T20:03:06.533Z
Link: CVE-2025-58446
Updated: 2025-09-08T17:55:08.296Z
Status : Analyzed
Published: 2025-09-06T19:15:38.733
Modified: 2025-09-18T15:57:02.380
Link: CVE-2025-58446
OpenCVE Enrichment
Updated: 2025-09-08T15:17:40Z
EUVD
Github GHSA