Denial of Service Vulnerability in xgrammar Library from mlc-ai
CVE-2025-58446
6.9MEDIUM
What is CVE-2025-58446?
The xgrammar library, an open-source tool for structured generation, contains a vulnerability in version 0.1.23 that can cause Denial of Service (DoS) for model providers by processing large grammars (over 100k characters) at significantly low rates. This flaw can lead to performance degradation and unresponsive services. The issue has been resolved in version 0.1.24, which is recommended for all users to ensure optimal functionality and security.
Affected Version(s)
xgrammar = 0.1.23, < 0.1.24