Skip to content
TransformersGHSA-59p9-h35m-wg4g

Hugging Face Transformers is vulnerable to ReDoS through its MarianTokenizer

Medium5.3CVE-2025-6638 · Published Sep 12, 2025 · updated Sep 10, 2026

A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically affecting the MarianTokenizer's `remove_language_code()` method. This vulnerability is present in version 4.52.4 and has been fixed in version 4.53.0. The issue arises from inefficient regex processing, which can be exploited by crafted input strings containing malformed language code patterns, leading to excessive CPU consumption and potential denial of service.

GitHub advisory

Affected versions

PackageAffectedFixed in
transformers
PyPI
< 4.53.04.53.0
Details and references

More Transformers advisories

All Transformers
Advisory
Transformers: denial of service
Medium5.3Sep 23, 2025
Hugging Face Transformers library has Regular Expression Denial of Service
Medium5.3Sep 14, 2025
Hugging Face Transformers Regular Expression Denial of Service (ReDoS) vulnerability
Medium5.3Aug 6, 2025
Transformers is vulnerable to ReDoS attack through its DonutProcessor class
Medium5.3Jul 11, 2025
Transformers vulnerable to ReDoS attack through its SETTING_RE variable
Medium5.3Jul 7, 2025
Transformers vulnerable to ReDoS attack through its get_imports() function
Medium5.3Jul 7, 2025

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.