PT-2025-37422 · Hugging Face · Huggingface/Transformers

Published

2025-06-09

·

Updated

2025-10-21

·

CVE-2025-6051

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Hugging Face Transformers versions up to 4.52.4
Description A Regular Expression Denial of Service (ReDoS) vulnerability exists in the normalize numbers() method of the EnglishNormalizer class. This issue arises from the method's handling of numeric strings, which can be exploited using crafted input strings containing long sequences of digits, leading to excessive CPU consumption. This impacts text-to-speech and number normalization tasks, potentially causing service disruption and resource exhaustion.
Recommendations Update to version 4.53.0 or later.

Fix

DoS

Weakness Enumeration

Related Identifiers

BDU:2025-12549
CVE-2025-6051
GHSA-RCV9-QM8P-9P6J

Affected Products

Huggingface/Transformers