VYPR

Transformers

by Huggingface

pypi: transformers

Source repositories

CVEs (33)

  • CVE-2025-3262HigJul 7, 2025
    risk 0.42cvss 7.5epss 0.00

    A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the huggingface/transformers repository, specifically in version 4.49.0. The vulnerability is due to inefficient regular expression complexity in the `SETTING_RE` variable within the…

  • CVE-2025-2099HigMay 19, 2025
    risk 0.42cvss 7.5epss 0.01

    A vulnerability in the `preprocess_string()` function of the `transformers.testing_utils` module in huggingface/transformers version v4.48.3 allows for a Regular Expression Denial of Service (ReDoS) attack. The regular expression used to process code blocks in docstrings…

  • CVE-2024-12720HigMar 20, 2025
    risk 0.42cvss 7.5epss 0.01

    A Regular Expression Denial of Service (ReDoS) vulnerability was identified in the huggingface/transformers library, specifically in the file tokenization_nougat_fast.py. The vulnerability occurs in the post_process_single() function, where a regular expression processes…

  • CVE-2026-9856HigAug 2, 2026
    risk 0.39cvss 7.1epss 0.00

    A vulnerability in huggingface/transformers versions <=5.8.0.dev0 allows an attacker to perform arbitrary file writes via path traversal. The issue resides in the `save_pretrained()` methods of `PreTrainedTokenizerBase` and `ProcessorMixin`, where keys from the `chat_template`…

  • CVE-2025-1194MedApr 29, 2025
    risk 0.35cvss 6.5epss 0.00

    A Regular Expression Denial of Service (ReDoS) vulnerability was identified in the huggingface/transformers library, specifically in the file `tokenization_gpt_neox_japanese.py` of the GPT-NeoX-Japanese model. The vulnerability occurs in the SubWordJapaneseTokenizer class, where…

  • CVE-2025-6051MedSep 14, 2025
    risk 0.27cvss 5.3epss 0.00

    A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically within the `normalize_numbers()` method of the `EnglishNormalizer` class. This vulnerability affects versions up to 4.52.4 and is fixed in version…

  • CVE-2025-5197MedAug 6, 2025
    risk 0.27cvss 5.3epss 0.00

    A Regular Expression Denial of Service (ReDoS) vulnerability exists in the Hugging Face Transformers library, specifically in the `convert_tf_weight_name_to_pt_weight_name()` function. This function, responsible for converting TensorFlow weight names to PyTorch format, uses a…

  • CVE-2025-3933MedJul 11, 2025
    risk 0.27cvss 5.3epss 0.00

    A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically within the DonutProcessor class's `token2json()` method. This vulnerability affects versions 4.50.3 and earlier, and is fixed in version 4.52.1. The…

  • CVE-2025-3264MedJul 7, 2025
    risk 0.27cvss 5.3epss 0.00

    A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically in the `get_imports()` function within `dynamic_module_utils.py`. This vulnerability affects versions 4.49.0 and is fixed in version 4.51.0. The…

  • CVE-2025-3263MedJul 7, 2025
    risk 0.27cvss 5.3epss 0.00

    A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically in the `get_configuration_file()` function within the `transformers.configuration_utils` module. The affected version is 4.49.0, and the issue is…

  • CVE-2023-2800MedMay 18, 2023
    risk 0.24cvss 4.7epss 0.00

    Insecure Temporary File in GitHub repository huggingface/transformers prior to 4.30.0.

  • CVE-2025-3777LowJul 7, 2025
    risk 0.16cvss 3.5epss 0.00

    Hugging Face Transformers versions up to 4.49.0 are affected by an improper input validation vulnerability in the `image_utils.py` file. The vulnerability arises from insecure URL validation using the `startswith()` method, which can be bypassed through URL username injection.…

  • CVE-2026-58116CriJun 30, 2026
    risk 0.00cvss 9.8epss 0.01

    LLaMA-Factory through 0.9.5 contains a remote code execution vulnerability that allows attackers with WebUI access to execute arbitrary Python code by supplying a malicious model path in the Chat or Training interfaces. The application passes user-supplied model path input…

Page 2 of 2