PT-2025-37422 · Hugging Face · Huggingface/Transformers
Published
2025-06-09
·
Updated
2025-10-21
·
CVE-2025-6051
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
Hugging Face Transformers versions up to 4.52.4
Description
A Regular Expression Denial of Service (ReDoS) vulnerability exists in the
normalize numbers() method of the EnglishNormalizer class. This issue arises from the method's handling of numeric strings, which can be exploited using crafted input strings containing long sequences of digits, leading to excessive CPU consumption. This impacts text-to-speech and number normalization tasks, potentially causing service disruption and resource exhaustion.Recommendations
Update to version 4.53.0 or later.
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Huggingface/Transformers