CVE-2025-3933

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-3933
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-3933.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-3933
Aliases
Published
2025-07-11T10:15:22Z
Modified
2025-07-15T15:47:58.892622Z
Summary
[none]
Details

A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically within the DonutProcessor class's token2json() method. This vulnerability affects versions 4.50.3 and earlier, and is fixed in version 4.52.1. The issue arises from the regex pattern <s_(.*?)> which can be exploited to cause excessive CPU consumption through crafted input strings due to catastrophic backtracking. This vulnerability can lead to service disruption, resource exhaustion, and potential API service vulnerabilities, impacting document processing tasks using the Donut model.

References

Affected packages

Git / github.com/huggingface/transformers

Affected ranges

Type
GIT
Repo
https://github.com/huggingface/transformers
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

0.*

0.1.2
0.5.0

1.*

1.0
1.1.0
1.2.0

3.*

3.0.1

4.*

4.3.0.rc1

v0.*

v0.1.2
v0.2.0
v0.3.0
v0.4.0
v0.5.0
v0.5.1
v0.6.0
v0.6.1
v0.6.2

v1.*

v1.0.0

v2.*

v2.0.0
v2.1.0
v2.1.1
v2.10.0
v2.11.0
v2.2.0
v2.2.1
v2.2.2
v2.3.0
v2.4.0
v2.4.1
v2.5.0
v2.5.1
v2.6.0
v2.7.0
v2.8.0
v2.9.0
v2.9.1

v3.*

v3.0.0
v3.0.1
v3.0.2
v3.1.0
v3.2.0
v3.3.0
v3.3.1
v3.4.0
v3.5.0

v4.*

v4.0.0-rc-1
v4.1.0
v4.1.1
v4.10.0
v4.11.0
v4.12.0
v4.13.0
v4.14.0
v4.15.0
v4.16.0
v4.2.0
v4.3.0.rc1
v4.33.1
v4.4.0
v4.49.0-AyaVision
v4.49.0-Mistral-3
v4.49.0-SigLIP-2
v4.49.0-SmolVLM-2
v4.5.0
v4.50.3-DeepSeek-3
v4.51.3-BitNet-preview
v4.51.3-D-FINE-preview
v4.51.3-GraniteMoeHybrid-preview
v4.51.3-InternVL-preview
v4.51.3-Janus-preview
v4.51.3-LlamaGuard-preview
v4.51.3-MLCD-preview
v4.51.3-Qwen2.5-Omni-preview
v4.51.3-SAM-HQ-preview
v4.51.3-TimesFM-preview
v4.6.0
v4.7.0
v4.8.0
v4.9.0