VYPR

Transformers

by Huggingface

pypi: transformers

Source repositories

CVEs (35)

  • CVE-2025-6638HigSep 12, 2025
    risk 0.42cvss 7.5epss 0.01

    A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically affecting the MarianTokenizer's `remove_language_code()` method. This vulnerability is present in version 4.52.4 and has been fixed in version…

  • CVE-2025-3262HigJul 7, 2025
    risk 0.42cvss 7.5epss 0.00

    A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the huggingface/transformers repository, specifically in version 4.49.0. The vulnerability is due to inefficient regular expression complexity in the `SETTING_RE` variable within the…

  • CVE-2025-2099HigMay 19, 2025
    risk 0.42cvss 7.5epss 0.01

    A vulnerability in the `preprocess_string()` function of the `transformers.testing_utils` module in huggingface/transformers version v4.48.3 allows for a Regular Expression Denial of Service (ReDoS) attack. The regular expression used to process code blocks in docstrings…

  • CVE-2024-12720HigMar 20, 2025
    risk 0.42cvss 7.5epss 0.01

    A Regular Expression Denial of Service (ReDoS) vulnerability was identified in the huggingface/transformers library, specifically in the file tokenization_nougat_fast.py. The vulnerability occurs in the post_process_single() function, where a regular expression processes…

  • CVE-2026-9856HigAug 2, 2026
    risk 0.39cvss 7.1epss 0.00

    A vulnerability in huggingface/transformers versions <=5.8.0.dev0 allows an attacker to perform arbitrary file writes via path traversal. The issue resides in the `save_pretrained()` methods of `PreTrainedTokenizerBase` and `ProcessorMixin`, where keys from the `chat_template`…

  • CVE-2026-75104MedAug 17, 2026
    risk 0.36cvss 5.5epss 0.00

    Hugging Face Transformers fails to validate shard filenames in checkpoint index files, allowing attackers to read arbitrary files outside the model directory. Attackers can supply malicious index files with parent-directory references or absolute paths that are joined without…

  • CVE-2025-1194MedApr 29, 2025
    risk 0.35cvss 6.5epss 0.00

    A Regular Expression Denial of Service (ReDoS) vulnerability was identified in the huggingface/transformers library, specifically in the file `tokenization_gpt_neox_japanese.py` of the GPT-NeoX-Japanese model. The vulnerability occurs in the SubWordJapaneseTokenizer class, where…

  • CVE-2025-6051MedSep 14, 2025
    risk 0.27cvss 5.3epss 0.00

    A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically within the `normalize_numbers()` method of the `EnglishNormalizer` class. This vulnerability affects versions up to 4.52.4 and is fixed in version…

  • CVE-2025-5197MedAug 6, 2025
    risk 0.27cvss 5.3epss 0.00

    A Regular Expression Denial of Service (ReDoS) vulnerability exists in the Hugging Face Transformers library, specifically in the `convert_tf_weight_name_to_pt_weight_name()` function. This function, responsible for converting TensorFlow weight names to PyTorch format, uses a…

  • CVE-2025-3933MedJul 11, 2025
    risk 0.27cvss 5.3epss 0.00

    A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically within the DonutProcessor class's `token2json()` method. This vulnerability affects versions 4.50.3 and earlier, and is fixed in version 4.52.1. The…

  • CVE-2025-3264MedJul 7, 2025
    risk 0.27cvss 5.3epss 0.00

    A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically in the `get_imports()` function within `dynamic_module_utils.py`. This vulnerability affects versions 4.49.0 and is fixed in version 4.51.0. The…

  • CVE-2025-3263MedJul 7, 2025
    risk 0.27cvss 5.3epss 0.00

    A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically in the `get_configuration_file()` function within the `transformers.configuration_utils` module. The affected version is 4.49.0, and the issue is…

  • CVE-2023-2800MedMay 18, 2023
    risk 0.24cvss 4.7epss 0.00

    Insecure Temporary File in GitHub repository huggingface/transformers prior to 4.30.0.

  • CVE-2025-3777LowJul 7, 2025
    risk 0.16cvss 3.5epss 0.00

    Hugging Face Transformers versions up to 4.49.0 are affected by an improper input validation vulnerability in the `image_utils.py` file. The vulnerability arises from insecure URL validation using the `startswith()` method, which can be bypassed through URL username injection.…

  • CVE-2026-58116CriJun 30, 2026
    risk 0.00cvss 9.8epss 0.01

    LLaMA-Factory through 0.9.5 contains a remote code execution vulnerability that allows attackers with WebUI access to execute arbitrary Python code by supplying a malicious model path in the Chat or Training interfaces. The application passes user-supplied model path input…

Page 2 of 2