Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-jjph-296x-mrcr: Transformers vulnerable to ReDoS attack through its get_imports() function

A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically in the get_imports() function within dynamic_module_utils.py. This vulnerability affects versions 4.49.0 and is fixed in version 4.51.0. The issue arises from a regular expression pattern \s*try\s*:.*?except.*?: used to filter out try/except blocks from Python code, which can be exploited to cause excessive CPU consumption through crafted input strings due to catastrophic backtracking. This vulnerability can lead to remote code loading disruption, resource exhaustion in model serving, supply chain attack vectors, and development pipeline disruption.

ghsa
#vulnerability#dos#git
  1. GitHub Advisory Database
  2. GitHub Reviewed
  3. CVE-2025-3264

Transformers vulnerable to ReDoS attack through its get_imports() function

Moderate severity GitHub Reviewed Published Jul 7, 2025 to the GitHub Advisory Database • Updated Jul 8, 2025

Package

pip transformers (pip)

Affected versions

< 4.51.0

Description

A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically in the get_imports() function within dynamic_module_utils.py. This vulnerability affects versions 4.49.0 and is fixed in version 4.51.0. The issue arises from a regular expression pattern \stry\s:.?except.?: used to filter out try/except blocks from Python code, which can be exploited to cause excessive CPU consumption through crafted input strings due to catastrophic backtracking. This vulnerability can lead to remote code loading disruption, resource exhaustion in model serving, supply chain attack vectors, and development pipeline disruption.

References

  • https://nvd.nist.gov/vuln/detail/CVE-2025-3264
  • huggingface/transformers@0720e20
  • https://huntr.com/bounties/3c6f7822-9992-476d-8cf0-b0b1623427df
  • huggingface/transformers@126abe3

Published to the GitHub Advisory Database

Jul 7, 2025

ghsa: Latest News

GHSA-xrrq-rrgq-h89w: static-alloc vulnerability leads to uninitialized read after allocating MemBump