Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fpwr-67px-3qhx

Опубликовано: 29 апр. 2025
Источник: github
Github: Прошло ревью
CVSS3: 4.3

Описание

Transformers Regular Expression Denial of Service (ReDoS) vulnerability

A Regular Expression Denial of Service (ReDoS) vulnerability was identified in the huggingface/transformers library, specifically in the file tokenization_gpt_neox_japanese.py of the GPT-NeoX-Japanese model. The vulnerability occurs in the SubWordJapaneseTokenizer class, where regular expressions process specially crafted inputs. The issue stems from a regex exhibiting exponential complexity under certain conditions, leading to excessive backtracking. This can result in high CPU usage and potential application downtime, effectively creating a Denial of Service (DoS) scenario. The affected version is v4.48.1 (latest).

Пакеты

Наименование

transformers

pip
Затронутые версииВерсия исправления

< 4.50.0

4.50.0

EPSS

Процентиль: 27%
0.00095
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-1333

Связанные уязвимости

CVSS3: 6.5
nvd
9 месяцев назад

A Regular Expression Denial of Service (ReDoS) vulnerability was identified in the huggingface/transformers library, specifically in the file `tokenization_gpt_neox_japanese.py` of the GPT-NeoX-Japanese model. The vulnerability occurs in the SubWordJapaneseTokenizer class, where regular expressions process specially crafted inputs. The issue stems from a regex exhibiting exponential complexity under certain conditions, leading to excessive backtracking. This can result in high CPU usage and potential application downtime, effectively creating a Denial of Service (DoS) scenario. The affected version is v4.48.1 (latest).

CVSS3: 4.3
fstec
9 месяцев назад

Уязвимость функции SubWordJapaneseTokenizer библиотеки Hugging Face Transformers, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 27%
0.00095
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-1333