CVE-2025-1194: Regular Expression Denial of Service (ReDoS) in huggingface/transformers
A Regular Expression Denial of Service (ReDoS) vulnerability was identified in the huggingface/transformers library, specifically in the file tokenizationgptneoxjapanese.py of the GPT-NeoX-Japanese model. The vulnerability occurs in the SubWordJapaneseTokenizer class, where regular expressions process specially crafted inputs. The issue stems from a regex exhibiting exponential complexity under certain conditions, leading to excessive backtracking. This can result in high CPU usage and potential application downtime, effectively creating a Denial of Service (DoS) scenario. The affected version is v4.48.1 (latest).
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1194?
CVE-2025-1194 is classified as a Regular Expression Denial of Service (ReDoS) vulnerability.
How do I fix CVE-2025-1194?
To fix CVE-2025-1194, update the huggingface/transformers library to the latest version where the vulnerability has been addressed.
What software is affected by CVE-2025-1194?
CVE-2025-1194 affects the Hugging Face Transformers library, specifically the GPT-NeoX-Japanese model.
What is the impact of CVE-2025-1194?
The impact of CVE-2025-1194 includes potential denial of service due to excessive time taken in regular expression processing.
In which file is CVE-2025-1194 found?
CVE-2025-1194 is found in the file tokenization_gpt_neox_japanese.py.