PT-2025-15757 · Xgrammar · Xgrammar

·

CVE-2025-32381

·

Published

2025-04-09

·

Updated

2025-09-17

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: XGrammar versions prior to 0.1.18
Description: The issue concerns an unbounded cache for compiled grammars in memory, which can be exploited to cause a denial of service by filling up a host's memory. This can occur when a system using XGrammar receives many small requests with unique JSON schemas, such as sending multiple requests to an LLM inference server.
Recommendations: For versions prior to 0.1.18, update to version 0.1.18 to resolve the issue.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-32381
GHSA-389X-67PX-MJG3
PYSEC-2025-235

Affected Products

Xgrammar