Regular Expression Denial of Service in Hugging Face Transformers Library
CVE-2025-6638
What is CVE-2025-6638?
A Regular Expression Denial of Service (ReDoS) vulnerability has been identified in the Hugging Face Transformers library, impacting the functionality of the MarianTokenizer's 'remove_language_code()' method. This flaw is triggered by inefficient regular expression processing, allowing an attacker to exploit the vulnerability using crafted input strings with malformed language code patterns. Such exploitation can lead to significant CPU resource exhaustion, resulting in potential denial of service for the application. The vulnerability is resolved in version 4.53.0, highlighting the importance of updating to the latest version to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
huggingface/transformers < 4.53.0
References
CVSS V3.0
Timeline
Vulnerability published
Vulnerability Reserved
