PT-2025-37307 · Hugging Face · Huggingface/Transformers

Published

2025-09-12

·

Updated

2025-09-12

·

CVE-2025-6638

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Hugging Face Transformers versions prior to 4.53.0
Description: A Regular Expression Denial of Service (ReDoS) vulnerability exists in the Hugging Face Transformers library, specifically affecting the remove language code() method within the MarianTokenizer. This issue arises from inefficient regular expression processing, which can be exploited by crafted input strings containing malformed language code patterns, leading to excessive CPU consumption and potential denial of service.
Recommendations: Update to version 4.53.0 or later.

Exploit

Fix

DoS

Weakness Enumeration

Related Identifiers

CVE-2025-6638
GHSA-59P9-H35M-WG4G

Affected Products

Huggingface/Transformers