HIGHPyPI →
XGrammar affected by Denial of Service by infinite recursion grammars
XGrammar affected by Denial of Service by infinite recursion grammars
Affected packages
- xgrammar— before 0.1.21
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- —
- EPSS percentile
- —
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.
Sources
- https://github.com/mlc-ai/xgrammar/security/advisories/GHSA-5cmr-4px5-23pc
- https://nvd.nist.gov/vuln/detail/CVE-2025-57809
- https://github.com/mlc-ai/xgrammar/issues/250
- https://github.com/mlc-ai/xgrammar/commit/b943feacb5a1caf4d39de8ec3bf7c7ce066dcee5
- https://github.com/mlc-ai/xgrammar
Structured record: https://osv.dev/vulnerability/GHSA-5cmr-4px5-23pc
Recommended response stack
Snyk — Scan your dependencies in CI and fix this vulnerability.→Socket — Detect malicious and compromised packages before they ship.→
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta