Home

Description

xgrammar is an open-source library for efficient, flexible, and portable structured generation. A grammar optimizer introduced in 0.1.23 processes large grammars (>100k characters) at very low rates, and can be used for DOS of model providers. This issue is fixed in version 0.1.24.

PUBLISHED Reserved 2025-09-01 | Published 2025-09-06 | Updated 2025-09-08 | Assigner GitHub_M




MEDIUM: 6.9CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

Problem types

CWE-770: Allocation of Resources Without Limits or Throttling

Product status

= 0.1.23, < 0.1.24
affected

References

github.com/...rammar/security/advisories/GHSA-9q5r-wfvf-rr7f

github.com/...ommit/ced69c3ad2f8f61b516cc278a342e7c644383e27

cve.org (CVE-2025-58446)

nvd.nist.gov (CVE-2025-58446)

Download JSON