AI Security Vulnerability
A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically within the `normalize_numbers()` method of the `EnglishNormalizer` class. This vulnerability affects versions up to 4.52.4 and is fixed in version 4.53.0. The issue arises from the method's handling of numeric strings, which can be exploited using crafted input strings containing long sequences of digits, leading to excessive CPU consumption. This vulnerability impacts text-to-speech and number normalization tasks, potentially causing service disruption, resource exhaustion, and API vulnerabilities.
RESOLVED
What Happened
A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically within the `normalize_numbers()` method of the `EnglishNormalizer` class. This vulnerability affects versions up to 4.52.4 and is fixed in version 4.53.0. The issue arises from the method's handling of numeric strings, which can be exploited using crafted input strings containing long sequences of digits, leading to excessive CPU consumption. This vulnerability impacts text-to-speech and number normalization tasks, potentially causing service disruption, resource exhaustion, and API vulnerabilities.
Why This Matters
Current evidence identifies a security issue involving Hugging Face Transformers, but does not yet support a more specific impact claim.
Recommended Action
No confirmed vendor remediation is available in the current evidence. Identify deployments of Hugging Face Transformers matching the evidenced affected versions: 4.52.4.
Exposure
Exposure unknown
Sep 15, 2025 00:00
Exposure reason: This incident does not currently match a technology in My Interests.
Exploitation status: UNKNOWN
Affected versions: 4.52.4
Primary entities:
Timeline
-
Incident first seen
Sep 15, 2025 00:00BugSkan first recorded this incident.
-
Hugging Face Transformers library has Regular Expression Denial of Service
Sep 15, 2025 00:00GitHub Advisory Database · Research
Sources
GitHub Advisory Database · Sep 15, 2025 00:00
A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically within the `normalize_numbers()` method of the `EnglishNormalizer` class. This vulnerability affects versions up to 4.52.4 and is fixed in version 4.53.0. The issue arises from the method's handling of numeric strings, which can be exploited using crafted input strings containing long sequences of digits, leading to excessive CPU consumption. This vulnerability impacts text-to-speech and number normalization tasks, potentially causing service disruption, resource exhaustion, and API vulnerabilities.
Open publisher sourceMy Interests Match
Create an account to see which incidents overlap with your interests.