CVE-2025-3262 is a Regular Expression Denial of Service (ReDoS) vulnerability affecting huggingface/transformers version 4.49.0. The flaw resides in the `SETTING_RE` regular expression within `transformers/commands/chat.py`, which contains inefficient patterns leading to exponential backtracking. This can be triggered by specially crafted input strings, causing application performance degradation and potential denial of service. The vulnerability has a CVSS score of 7.5 (HIGH), indicating a severe impact on availability (A:H) with no user interaction required (UI:N) and low attack complexity (AC:L) over the network (AV:N). While it does not allow for data compromise, it poses a significant risk to service uptime. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. The CVE has received minimal community discussion and media coverage, suggesting a low level of public awareness at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.51.0CPE matchmatch criteria | cpe:2.3:a:huggingface:transformers:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.