CVE Explorer
CVE-2025-6638
A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically affecting the MarianTokenizer's `remove_language_code()` method. This vulnerability is present in version 4.52.4 and has been fixed in version 4.53.0. The issue arises from inefficient regex processing, which can be exploited by crafted input strings containing malformed language code patterns, leading to excessive CPU consumption and potential denial of service.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"huggingface/transformers","vendor":"huggingface","versions":[{"lessThan":"4.53.0","status":"affected","version":"unspecified","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:6ee368c6e11e8e34c86e9303acfb828b182baa9a165effb6ffcf769fe7da84c6 · sha256:1880e7e1b12fe96d… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":5.3,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","version":"3.0"},"metric_type":"cvssV3_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:6ee368c6e11e8e34c86e9303acfb828b182baa9a165effb6ffcf769fe7da84c6 · sha256:1880e7e1b12fe96d… · /containers/cna/metrics/0/cvssV3_0
CWE assertions
1 source assertion{"cweId":"CWE-1333","description":"CWE-1333 Inefficient Regular Expression Complexity","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:6ee368c6e11e8e34c86e9303acfb828b182baa9a165effb6ffcf769fe7da84c6 · sha256:1880e7e1b12fe96d… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"url":"https://github.com/huggingface/transformers/commit/47c34fba5c303576560cb29767efb452ff12b8be"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:6ee368c6e11e8e34c86e9303acfb828b182baa9a165effb6ffcf769fe7da84c6 · sha256:1880e7e1b12fe96d… · /containers/cna/references/1
{"url":"https://huntr.com/bounties/6a6c933f-9ce8-4ded-8b3b-2c1444c61f36"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:6ee368c6e11e8e34c86e9303acfb828b182baa9a165effb6ffcf769fe7da84c6 · sha256:1880e7e1b12fe96d… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.