CVE-2025-3264

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-3264
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-3264.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-3264
Aliases
Published
2025-07-07T10:15:27Z
Modified
2025-07-09T14:02:45.567755Z
Summary
[none]
Details

A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically in the get_imports() function within dynamic_module_utils.py. This vulnerability affects versions 4.49.0 and is fixed in version 4.51.0. The issue arises from a regular expression pattern \s*try\s*:.*?except.*?: used to filter out try/except blocks from Python code, which can be exploited to cause excessive CPU consumption through crafted input strings due to catastrophic backtracking. This vulnerability can lead to remote code loading disruption, resource exhaustion in model serving, supply chain attack vectors, and development pipeline disruption.

References

Affected packages

Git / github.com/huggingface/transformers

Affected ranges

Type
GIT
Repo
https://github.com/huggingface/transformers
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

0.*

0.1.2
0.5.0

1.*

1.0
1.1.0
1.2.0

3.*

3.0.1

4.*

4.3.0.rc1

v0.*

v0.1.2
v0.2.0
v0.3.0
v0.4.0
v0.5.0
v0.5.1
v0.6.0
v0.6.1
v0.6.2

v1.*

v1.0.0

v2.*

v2.0.0
v2.1.0
v2.1.1
v2.10.0
v2.11.0
v2.2.0
v2.2.1
v2.2.2
v2.3.0
v2.4.0
v2.4.1
v2.5.0
v2.5.1
v2.6.0
v2.7.0
v2.8.0
v2.9.0
v2.9.1

v3.*

v3.0.0
v3.0.1
v3.0.2
v3.1.0
v3.2.0
v3.3.0
v3.3.1
v3.4.0
v3.5.0

v4.*

v4.0.0-rc-1
v4.1.0
v4.1.1
v4.10.0
v4.11.0
v4.12.0
v4.13.0
v4.14.0
v4.15.0
v4.16.0
v4.2.0
v4.3.0.rc1
v4.33.1
v4.4.0
v4.49.0-AyaVision
v4.49.0-Mistral-3
v4.49.0-SigLIP-2
v4.49.0-SmolVLM-2
v4.5.0
v4.50.3-DeepSeek-3
v4.6.0
v4.7.0
v4.8.0
v4.9.0