High severity7.5NVD Advisory· Published Sep 6, 2025· Updated Jun 17, 2026
CVE-2025-58446
CVE-2025-58446
Description
xgrammar is an open-source library for efficient, flexible, and portable structured generation. A grammar optimizer introduced in 0.1.23 processes large grammars (>100k characters) at very low rates, and can be used for DOS of model providers. This issue is fixed in version 0.1.24.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
xgrammarPyPI | >= 0.1.23, < 0.1.24 | 0.1.24 |
Affected products
5- ghsa-coords3 versionspkg:pypi/xgrammarpkg:apk/chainguard/tritonserver-backend-vllm-cuda-12.9pkg:apk/chainguard/tritonserver-backend-vllm-meta-cuda-12.9
>= 0.1.23, < 0.1.24+ 2 more
- (no CPE)range: >= 0.1.23, < 0.1.24
- (no CPE)range: < 25.7.1_git20251001-r1
- (no CPE)range: < 25.7.1_git20251001-r1
Patches
Vulnerability mechanics
References
4- github.com/mlc-ai/xgrammar/commit/ced69c3ad2f8f61b516cc278a342e7c644383e27nvdPatchWEB
- github.com/mlc-ai/xgrammar/security/advisories/GHSA-9q5r-wfvf-rr7fnvdExploitVendor AdvisoryWEB
- github.com/advisories/GHSA-9q5r-wfvf-rr7fghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2025-58446ghsaADVISORY
News mentions
0No linked articles in our index yet.