CVE-2025-2099

CVE Details

Basic Information

Title CVE-2025-2099
Type cve
Published 2025-05-19T12:15:19
Last Seen 2025-05-19T12:18:10

CVSS Information

Base Score 5.3 (MEDIUM)
Attack Vector NETWORK
Attack Complexity LOW
Privileges Required NONE
User Interaction NONE
Scope UNCHANGED
Confidentiality Impact NONE
Integrity Impact NONE
Availability Impact LOW

AI Analysis

AI Description A vulnerability in the preprocess_string() function of the transformers.testing_utils module in Hugging Face’s transformers library (version v4.48.3) allows a Regular Expression Denial of Service (ReDoS) attack, which could cause service disruptions.
AI Severity Medium
Vendor Hugging Face
Product transformers
Affected Version v4.48.3

Additional Information

CVE List CVE-2025-2099
CWE List CWE-1333
Bulletin Family cve

Description

A vulnerability in the preprocess_string() function of the transformers.testing_utils module in huggingface/transformers version v4.48.3 allows for a Regular Expression Denial of Service (ReDoS) attack….

CVSS Score Summary

Base Score: %!f(string=#) (MEDIUM)

View Full CVE Details

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.