CVE-2025-6638 - CVE House
Back to Database
Status published Medium CVE-2025-6638

Regular Expression Denial of Service (ReDoS) in huggingface/transformers

Vulnerability Description

A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically affecting the MarianTokenizer's `remove_language_code()` method. This vulnerability is present in version 4.52.4 and has been fixed in version 4.53.0. The issue arises from inefficient regex processing, which can be exploited by crafted input strings containing malformed language code patterns, leading to excessive CPU consumption and potential denial of service.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-6638

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

huggingface

View all reports →

Affected Software

huggingface/transformers
Vulnerable Versions:
unspecified

Timeline

Official Publish: September 12th, 2025
Last Modified: September 12th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Weaknesses (CWE)