PT-2025-39174 · Hugging Face · Transformers
CVE-2025-6921
·
Publicado
2025-06-18
·
Atualizado
2026-08-11
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
huggingface/transformers versions prior to 4.53.0
Description
The software is susceptible to a Regular Expression Denial of Service (ReDoS) within the AdamWeightDecay optimizer. The issue stems from the
do use weight decay method, which handles user-provided regular expressions found in the include in weight decay and exclude from weight decay lists. Specifically, malicious regular expressions can trigger catastrophic backtracking during the re.search call, resulting in high CPU usage and a denial of service. Attackers controlling these patterns can potentially disrupt machine learning tasks and cause services to become unresponsive.Recommendations
Update to version 4.53.0 or later.
Exploit
Correção
DoS
Resource Exhaustion
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Transformers