PT-2025-37307 · Hugging Face · Huggingface/Transformers

CVE-2025-6638

·

Published

2025-09-12

·

Updated

2026-07-07

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Hugging Face Transformers versions prior to 4.53.0
Description: A Regular Expression Denial of Service (ReDoS) vulnerability exists in the Hugging Face Transformers library, specifically affecting the remove language code() method within the MarianTokenizer. This issue arises from inefficient regular expression processing, which can be exploited by crafted input strings containing malformed language code patterns, leading to excessive CPU consumption and potential denial of service.
Recommendations: Update to version 4.53.0 or later.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-6638
GHSA-59P9-H35M-WG4G
PYSEC-2026-1981

Affected Products

Huggingface/Transformers