Metrics
Affected Vendors & Products
Thu, 25 Sep 2025 08:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Huggingface
Huggingface transformers |
|
Vendors & Products |
Huggingface
Huggingface transformers |
Wed, 24 Sep 2025 00:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
| |
Metrics |
threat_severity
|
cvssV3_1
|
Tue, 23 Sep 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 23 Sep 2025 14:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The huggingface/transformers library, versions prior to 4.53.0, is vulnerable to Regular Expression Denial of Service (ReDoS) in the AdamWeightDecay optimizer. The vulnerability arises from the _do_use_weight_decay method, which processes user-controlled regular expressions in the include_in_weight_decay and exclude_from_weight_decay lists. Malicious regular expressions can cause catastrophic backtracking during the re.search call, leading to 100% CPU utilization and a denial of service. This issue can be exploited by attackers who can control the patterns in these lists, potentially causing the machine learning task to hang and rendering services unresponsive. | |
Title | Regular Expression Denial of Service (ReDoS) in huggingface/transformers | |
Weaknesses | CWE-400 | |
References |
| |
Metrics |
cvssV3_0
|

Status: PUBLISHED
Assigner: @huntr_ai
Published:
Updated: 2025-09-23T14:56:29.038Z
Reserved: 2025-06-30T09:44:12.092Z
Link: CVE-2025-6921

Updated: 2025-09-23T14:56:25.327Z

Status : Awaiting Analysis
Published: 2025-09-23T14:15:41.387
Modified: 2025-09-24T18:11:24.520
Link: CVE-2025-6921
