CVE 6.9 MEDIUM

xgrammar vulnerable to denial of service by huge enum grammar_CVE-2025-58446

6.9 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

Description

xgrammar is an open-source library for efficient, flexible, and portable structured generation. A grammar optimizer introduced in 0.1.23 processes large grammars (>100k characters) at very low rates, and can be used for DOS of model providers. This issue is fixed in version 0.1.24.

Basic Information

ID CVE-2025-58446
Source GitHub_M
Published Sep 6, 2025 at 19:06

Affected Product

Vendor mlc-ai
Product xgrammar
Version = 0.1.23, < 0.1.24
Affected Versions mlc-ai xgrammar = 0.1.23, < 0.1.24

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.