PT-2025-39174 · Hugging Face · Transformers

CVE-2025-6921

·

Publicado

2025-06-18

·

Atualizado

2026-08-11

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions huggingface/transformers versions prior to 4.53.0
Description The software is susceptible to a Regular Expression Denial of Service (ReDoS) within the AdamWeightDecay optimizer. The issue stems from the do use weight decay method, which handles user-provided regular expressions found in the include in weight decay and exclude from weight decay lists. Specifically, malicious regular expressions can trigger catastrophic backtracking during the re.search call, resulting in high CPU usage and a denial of service. Attackers controlling these patterns can potentially disrupt machine learning tasks and cause services to become unresponsive.
Recommendations Update to version 4.53.0 or later.

Exploit

Correção

DoS

Resource Exhaustion

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2025-12550
CVE-2025-6921
GHSA-4W7R-H757-3R74
OPENSUSE-SU-2026:11499-1
PYSEC-2026-1980

Produtos afetados

Transformers