Last seen July 11, 2025

AI Security Vulnerability

A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically within the DonutProcessor class's `token2json()` method. This vulnerability affects versions 4.51.3 and earlier, and is fixed in version 4.52.1. The issue arises from the regex pattern ` ` which can be exploited to cause excessive CPU consumption through crafted input strings due to catastrophic backtracking. This vulnerability can lead to service disruption, resource exhaustion, and potential API service vulnerabilities, impacting document processing tasks using the Donut model.

Technical Severity
Low severity
Lifecycle Status

RESOLVED

What Happened

A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically within the DonutProcessor class's `token2json()` method. This vulnerability affects versions 4.51.3 and earlier, and is fixed in version 4.52.1. The issue arises from the regex pattern ` ` which can be exploited to cause excessive CPU consumption through crafted input strings due to catastrophic backtracking. This vulnerability can lead to service disruption, resource exhaustion, and potential API service vulnerabilities, impacting document processing tasks using the Donut model.

Why This Matters

Current evidence identifies a security issue involving DonutProcessor, but does not yet support a more specific impact claim.

Recommended Action

No confirmed vendor remediation is available in the current evidence. Identify deployments of DonutProcessor matching the evidenced affected versions: 4.51.3.

Exposure

My Interests Exposure

Exposure unknown

Recommended Response
Last Seen

Jul 11, 2025 18:00

Exposure reason: This incident does not currently match a technology in My Interests.

Exploitation status: UNKNOWN

Affected versions: 4.51.3

Primary entities:

Remote Code ExecutionvulnerabilityDonutProcessorReDoShuggingface/transformers

Timeline

  • Incident first seen
    Jul 11, 2025 18:00

    BugSkan first recorded this incident.

  • Transformers is vulnerable to ReDoS attack through its DonutProcessor class
    Jul 11, 2025 18:00

    OSV.dev · Research

Sources

Transformers is vulnerable to ReDoS attack through its DonutProcessor class

OSV.dev · Jul 11, 2025 18:00

A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically within the DonutProcessor class's `token2json()` method. This vulnerability affects versions 4.51.3 and earlier, and is fixed in version 4.52.1. The issue arises from the regex pattern ` ` which can be exploited to cause excessive CPU consumption through crafted input strings due to catastrophic backtracking. This vulnerability can lead to service disruption, resource exhaustion, and potential API service vulnerabilities, impacting document processing tasks using the Donut model.

Open publisher source

My Interests Match

Want personalized relevance?

Create an account to see which incidents overlap with your interests.

← Back to incident intelligence