AI Security Vulnerability
A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically within the DonutProcessor class's `token2json()` method. This vulnerability affects versions 4.51.3 and earlier, and is fixed in version 4.52.1. The issue arises from the regex pattern ` ` which can be exploited to cause excessive CPU consumption through crafted input strings due to catastrophic backtracking. This vulnerability can lead to service disruption, resource exhaustion, and potential API service vulnerabilities, impacting document processing tasks using the Donut model.
What Happened
A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically within the DonutProcessor class's `token2json()` method. This vulnerability affects versions 4.51.3 and earlier, and is fixed in version 4.52.1. The issue arises from the regex pattern ` ` which can be exploited to cause excessive CPU consumption through crafted input strings due to catastrophic backtracking. This vulnerability can lead to service disruption, resource exhaustion, and potential API service vulnerabilities, impacting document processing tasks using the Donut model.
Why This Matters
Current evidence identifies a security issue involving DonutProcessor, but does not yet support a more specific impact claim.
Recommended Action
No confirmed vendor remediation is available in the current evidence. Identify deployments of DonutProcessor matching the evidenced affected versions: 4.51.3.
Exposure
Exposure unknown
Jul 11, 2025 18:00
Exposure reason: This incident does not currently match a technology in My Interests.
Exploitation status: UNKNOWN
Affected versions: 4.51.3
Primary entities:
Timeline
-
Incident first seen
Jul 11, 2025 18:00BugSkan first recorded this incident.
-
Transformers is vulnerable to ReDoS attack through its DonutProcessor class
Jul 11, 2025 18:00OSV.dev · Research
Sources
OSV.dev · Jul 11, 2025 18:00
A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically within the DonutProcessor class's `token2json()` method. This vulnerability affects versions 4.51.3 and earlier, and is fixed in version 4.52.1. The issue arises from the regex pattern ` ` which can be exploited to cause excessive CPU consumption through crafted input strings due to catastrophic backtracking. This vulnerability can lead to service disruption, resource exhaustion, and potential API service vulnerabilities, impacting document processing tasks using the Donut model.
Open publisher sourceMy Interests Match
Create an account to see which incidents overlap with your interests.