← Vulnerability feed

Vulnerability record · CVE-2025-6638 · published 12 September 2025

CVE-2025-6638: Huggingface transformers inefficient regular expression (redos) vulnerability

Huggingface · Transformers

A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically affecting the MarianTokenizer's `remove_language_code()` method. This vulnerability is present in version 4.52.4 and has been fixed in version 4.53.0. The issue arises from inefficient regex processing, which can be exploited by crafted input strings containing malformed language code patterns, leading to excessive CPU consumption and potential denial of service.

7.5 CVSS 3.1 High EPSS 0.53% · top 57.5% CWE-1333 · Inefficient regular expression (ReDoS)
7.5CVSS 3.1 base score
0.53%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically affecting the MarianTokenizer's `remove_language_code()` method. This vulnerability is present in version 4.52.4 and has been fixed in version 4.53.0. The issue arises from inefficient regex processing, which can be exploited by crafted input strings containing malformed language code patterns, leading to excessive CPU consumption and potential denial of service.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-6638 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.6CVE-2026-5241Huggingface transformers inclusion from untrusted sphere vulnerabilityA vulnerability in the LightGlue model loading path of huggingface/transformers version 5.2.0 allows an attacker-controlled model repository to execu…EPSS 0.94%9.6CVE-2024-3568Huggingface transformers deserialization of untrusted data vulnerabilityThe huggingface/transformers library is vulnerable to arbitrary code execution through deserialization of untrusted data within the `load_repo_checkp…EPSS 2.1%8.8CVE-2024-11393Huggingface transformers deserialization of untrusted data vulnerabilityHugging Face Transformers MaskFormer Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote at…EPSS 3.1%8.8CVE-2024-11394Huggingface transformers deserialization of untrusted data vulnerabilityHugging Face Transformers Trax Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attacker…EPSS 2.6%8.8CVE-2024-11392Huggingface transformers deserialization of untrusted data vulnerabilityHugging Face Transformers MobileViTV2 Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attacke…EPSS 7.3%8.8CVE-2023-6730Huggingface transformers deserialization of untrusted data vulnerabilityDeserialization of Untrusted Data in GitHub repository huggingface/transformers prior to 4.36.EPSS 0.93%7.8CVE-2026-4372Huggingface transformers deserialization of untrusted data vulnerabilityA critical remote code execution vulnerability exists in all versions of the HuggingFace transformers library prior to version 5.3.0. The vulnerabili…EPSS 0.60%7.8CVE-2026-1839Huggingface transformers deserialization of untrusted data vulnerabilityA vulnerability in the HuggingFace Transformers library, specifically in the `Trainer` class, allows for arbitrary code execution. The `_load_rng_sta…EPSS 0.38%

Source: NIST National Vulnerability Database (record CVE-2025-6638), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.