Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-57809

25
FAUCET Score

CVE-2025-57809 describes an infinite recursion vulnerability in the XGrammar library, affecting versions prior to 0.1.21. This high-severity vulnerability (CVSS 7.5) can be exploited remotely without user interaction, leading to a denial-of-service condition. While no active exploitation, public exploit code, or significant community discussion has been observed, organizations using affected versions of mlc_ai xgrammar should prioritize updating to mitigate this risk.

Impacted Technologies

VendorProductVersion(s)CPE
< 0.1.21CPE matchmatch criteria
cpe:2.3:a:mlc-ai:xgrammar:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

7.7HIGH

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
NONE
VS Integrity
NONE
VS Availability
HIGH
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
PROOF_OF_CONCEPT
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.46%
Probability of exploitation in next 30 days
EPSS Percentile
37.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0046 is in the 16th percentile among its peer group of 51,506 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (14)

github_advisorypatch availablevia nvd_reference
View patch
pippatch availablevia ghsa
Product: xgrammarFixed in: 0.1.21
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux AI 1.5Fixed in: rhelai1/instructlab-intel-rhel9:sha256:cf0ec4ad1520ff2ce83420846830286e036f310f880cf8a533f0966c35ebd32f
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux AI 1.5Fixed in: rhelai1/bootc-intel-rhel9:sha256:601064840ac29ea7d4a977efb506df226a2931d5079ec9f432bdf60095bf7c2e
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux AI 1.5Fixed in: rhelai1/instructlab-nvidia-rhel9:sha256:a7e2df4276aaba0d23430c7c3314e05b005fe5628d588bc1f4f979a35571fa5c
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux AI 1.5Fixed in: rhelai1/bootc-azure-amd-rhel9:sha256:f77167ea53b46b91631679ed84aab2373ff56dc62cba946296be212443bc2a99
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux AI 1.5Fixed in: rhelai1/instructlab-amd-rhel9:sha256:03f22e965af16fe84aed7d30e7b8db00dead11d9fd4b11e3c9abb2e68dd910f1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux AI 1.5Fixed in: rhelai1/bootc-gcp-nvidia-rhel9:sha256:a83229f005c78e271c774f3eda26421fedbc4b8cf1ac3fe94234899c6d677124
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux AI 1.5Fixed in: rhelai1/bootc-amd-rhel9:sha256:c029b66a3354ee6fd186a1f05aff31b5834e611b9d5b326b65b16829d6b98d1f
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux AI 1.5Fixed in: rhelai1/bootc-nvidia-rhel9:sha256:dd412fc0dde3dee492839c28f8ed003bb17fe5fe1be375031b24c84bb36fb8cd
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux AI 1.5Fixed in: rhelai1/bootc-aws-nvidia-rhel9:sha256:385028a96717418982de197f8f0a9052edf12f80a50bd8ab53ca72203a4ba5d8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux AI 1.5Fixed in: rhelai1/bootc-azure-nvidia-rhel9:sha256:427596ae2591a30a0218b7cfdd858ccad96178ddc2618cdf0a6e4e9af36685bf
View patch
redhatno patchvia redhat_api
Product: Red Hat AI Inference ServerFixed in: rhaiis/vllm-cuda-rhel9
redhatno patchvia redhat_api
Product: Red Hat AI Inference ServerFixed in: rhaiis/vllm-rocm-rhel9

Vendor Advisories (2)

redhatCVE-2025-57809Important

xgrammar: XGrammar affected by Denial of Service by infinite recursion grammars

Aug 25, 2025
pipGHSA-5cmr-4px5-23pchigh

XGrammar affected by Denial of Service by infinite recursion grammars

Aug 25, 2025

References

github.com / mlc-ai/xgrammar/commit/b943feacb5a1caf4d39de8ec3bf7c7ce066dcee5
Patch
github.com / mlc-ai/xgrammar/issues/250
ExploitIssue Tracking
github.com / mlc-ai/xgrammar/security/advisories/GHSA-5cmr-4px5-23pc
Vendor Advisory