📦 Transformers

by Huggingface

🔍 What is Transformers?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-3568

CRITICAL CVSS 9.6 Apr 10, 2024

The huggingface/transformers library contains a critical vulnerability allowing arbitrary code execution through malicious serialized checkpoints. Attackers can execute commands on victim machines by ...

CVE-2025-6921

HIGH CVSS 7.5 Sep 23, 2025

This CVE describes a Regular Expression Denial of Service (ReDoS) vulnerability in the huggingface/transformers library's AdamWeightDecay optimizer. Attackers who can control regular expression patter...

CVE-2025-3262

HIGH CVSS 7.5 Jul 7, 2025

A Regular Expression Denial of Service (ReDoS) vulnerability in huggingface/transformers allows attackers to degrade application performance or cause denial-of-service by sending specially crafted inp...

CVE-2024-12720

HIGH CVSS 7.5 Mar 20, 2025

A Regular Expression Denial of Service (ReDoS) vulnerability exists in the huggingface/transformers library's tokenization_nougat_fast.py file. The post_process_single() function uses a regex that can...

CVE-2024-11394

HIGH CVSS 8.8 Nov 22, 2024

This vulnerability allows remote attackers to execute arbitrary code by tricking users into loading malicious model files in Hugging Face Transformers. Attackers can achieve remote code execution in t...

CVE-2024-11392

HIGH CVSS 8.8 Nov 22, 2024

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of Hugging Face Transformers with MobileViTV2. Attackers can exploit this by tricking users ...

CVE-2023-6730

HIGH CVSS 8.8 Dec 19, 2023

This vulnerability in the Hugging Face Transformers library allows remote code execution through unsafe deserialization of untrusted data. Attackers can exploit this by providing malicious serialized ...

CVE-2025-5197

MEDIUM CVSS 5.3 Aug 6, 2025

A Regular Expression Denial of Service (ReDoS) vulnerability in Hugging Face Transformers allows attackers to cause excessive CPU consumption by providing specially crafted weight names to the model c...

CVE-2025-3264

MEDIUM CVSS 5.3 Jul 7, 2025

A Regular Expression Denial of Service (ReDoS) vulnerability in Hugging Face Transformers library allows attackers to cause excessive CPU consumption by providing specially crafted input strings to th...