Skip to main content

Vendor/product archive

huggingface / transformers CVEs

Beta · best-effort

30 CVEs tagged to huggingface / transformers2 Critical, 20 High, 7 Medium, 1 Low, 0 Unrated.

CVE-2026-5241

Published Jun 3, 2026

A vulnerability in the LightGlue model loading path of huggingface/transformers version 5.2.0 allows an attacker-controlled model repository to execute arbitrary code during model…

CVSS 9.6 · Critical
evidence mentions
8
Buzz score
36.5
Vendor/product tagsBeta · best-effort

CVE-2026-4372

Published May 24, 2026

A critical remote code execution vulnerability exists in all versions of the HuggingFace transformers library prior to version 5.3.0. The vulnerability allows an attacker to craft…

CVSS 7.8 · High
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-1839

Published Apr 7, 2026

A vulnerability in the HuggingFace Transformers library, specifically in the `Trainer` class, allows for arbitrary code execution. The `_load_rng_state()` method in `src/transform…

CVSS 7.8 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2025-14930

Published Dec 23, 2025

Hugging Face Transformers GLM4 Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affec…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-14929

Published Dec 23, 2025

Hugging Face Transformers X-CLIP Checkpoint Conversion Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-14928

Published Dec 23, 2025

Hugging Face Transformers HuBERT convert_config Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affecte…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-14927

Published Dec 23, 2025

Hugging Face Transformers SEW-D convert_config Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-14926

Published Dec 23, 2025

Hugging Face Transformers SEW convert_config Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected i…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-14924

Published Dec 23, 2025

Hugging Face Transformers megatron_gpt2 Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-14921

Published Dec 23, 2025

Hugging Face Transformers Transformer-XL Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitra…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-14920

Published Dec 23, 2025

Hugging Face Transformers Perceiver Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary co…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-6921

Published Sep 23, 2025

The huggingface/transformers library, versions prior to 4.53.0, is vulnerable to Regular Expression Denial of Service (ReDoS) in the AdamWeightDecay optimizer. The vulnerability a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-6051

Published Sep 14, 2025

A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically within the `normalize_numbers()` method of the `…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-6638

Published Sep 12, 2025

A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically affecting the MarianTokenizer's `remove_language…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-5197

Published Aug 6, 2025

A Regular Expression Denial of Service (ReDoS) vulnerability exists in the Hugging Face Transformers library, specifically in the `convert_tf_weight_name_to_pt_weight_name()` func…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-3933

Published Jul 11, 2025

A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically within the DonutProcessor class's `token2json()`…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-3777

Published Jul 7, 2025

Hugging Face Transformers versions up to 4.49.0 are affected by an improper input validation vulnerability in the `image_utils.py` file. The vulnerability arises from insecure URL…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-3264

Published Jul 7, 2025

A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically in the `get_imports()` function within `dynamic_…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-3263

Published Jul 7, 2025

A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically in the `get_configuration_file()` function withi…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-3262

Published Jul 7, 2025

A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the huggingface/transformers repository, specifically in version 4.49.0. The vulnerability is due to…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-2099

Published May 19, 2025

A vulnerability in the `preprocess_string()` function of the `transformers.testing_utils` module in huggingface/transformers version v4.48.3 allows for a Regular Expression Denial…

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2025-1194

Published Apr 29, 2025

A Regular Expression Denial of Service (ReDoS) vulnerability was identified in the huggingface/transformers library, specifically in the file `tokenization_gpt_neox_japanese.py` o…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2024-12720

Published Mar 20, 2025

A Regular Expression Denial of Service (ReDoS) vulnerability was identified in the huggingface/transformers library, specifically in the file tokenization_nougat_fast.py. The vuln…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-11394

Published Nov 22, 2024

Hugging Face Transformers Trax Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-11393

Published Nov 22, 2024

Hugging Face Transformers MaskFormer Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary c…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 30 CVEsPage 1 of 2