Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
45 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.38% | — | Huggingface Transformers | 14/9/2025 | 30/9/2026 | A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically within the `normalize_numbers()` method of the `EnglishNormalizer` class. This vulnerability affects versions up to 4.52.4 and is fixed in version 4.53.0. The issue arises from the… | |
| Analizada | Alta (7.5) | 0.53% | — | Huggingface Transformers | 12/9/2025 | 17/6/2026 | A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically affecting the MarianTokenizer's `remove_language_code()` method. This vulnerability is present in version 4.52.4 and has been fixed in version 4.53.0. The issue arises from inefficient… | |
| Aplazada | Alta (7.8) | 0.74% | — | Nvidia Merlin Transformers4recAI | 13/8/2025 | 17/6/2026 | NVIDIA Merlin Transformers4Rec for all platforms contains a vulnerability in a python dependency, where an attacker could cause a code injection issue. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering. | |
| Analizada | Media (5.3) | 0.40% | — | Huggingface Transformers | 6/8/2025 | 17/6/2026 | A Regular Expression Denial of Service (ReDoS) vulnerability exists in the Hugging Face Transformers library, specifically in the `convert_tf_weight_name_to_pt_weight_name()` function. This function, responsible for converting TensorFlow weight names to PyTorch format, uses a regex pattern `/[^/]*___([^/]*)/` that can… | |
| Analizada | Media (5.3) | 0.46% | — | Huggingface Transformers | 11/7/2025 | 17/6/2026 | A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically within the DonutProcessor class's `token2json()` method. This vulnerability affects versions 4.50.3 and earlier, and is fixed in version 4.52.1. The issue arises from the regex pattern… | |
| Analizada | Baja (3.5) | 0.38% | — | Huggingface Transformers | 7/7/2025 | 17/6/2026 | Hugging Face Transformers versions up to 4.49.0 are affected by an improper input validation vulnerability in the `image_utils.py` file. The vulnerability arises from insecure URL validation using the `startswith()` method, which can be bypassed through URL username injection. This allows attackers to craft URLs that… | |
| Analizada | Media (5.3) | 0.46% | — | Huggingface Transformers | 7/7/2025 | 17/6/2026 | A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically in the `get_imports()` function within `dynamic_module_utils.py`. This vulnerability affects versions 4.49.0 and is fixed in version 4.51.0. The issue arises from a regular expression… | |
| Analizada | Media (5.3) | 0.46% | — | Huggingface Transformers | 7/7/2025 | 17/6/2026 | A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically in the `get_configuration_file()` function within the `transformers.configuration_utils` module. The affected version is 4.49.0, and the issue is resolved in version 4.51.0. The… | |
| Analizada | Alta (7.5) | 0.46% | — | Huggingface Transformers | 7/7/2025 | 17/6/2026 | A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the huggingface/transformers repository, specifically in version 4.49.0. The vulnerability is due to inefficient regular expression complexity in the `SETTING_RE` variable within the `transformers/commands/chat.py` file. The regex contains… | |
| Analizada | Alta (7.5) | 0.58% | — | Huggingface Transformers | 19/5/2025 | 17/6/2026 | A vulnerability in the `preprocess_string()` function of the `transformers.testing_utils` module in huggingface/transformers version v4.48.3 allows for a Regular Expression Denial of Service (ReDoS) attack. The regular expression used to process code blocks in docstrings contains nested quantifiers, leading to… | |
| Analizada | Media (6.5) | 0.48% | — | Huggingface Transformers | 29/4/2025 | 17/6/2026 | A Regular Expression Denial of Service (ReDoS) vulnerability was identified in the huggingface/transformers library, specifically in the file `tokenization_gpt_neox_japanese.py` of the GPT-NeoX-Japanese model. The vulnerability occurs in the SubWordJapaneseTokenizer class, where regular expressions process specially… | |
| Analizada | Alta (7.5) | 0.73% | — | Huggingface Transformers | 20/3/2025 | 17/6/2026 | A Regular Expression Denial of Service (ReDoS) vulnerability was identified in the huggingface/transformers library, specifically in the file tokenization_nougat_fast.py. The vulnerability occurs in the post_process_single() function, where a regular expression processes specially crafted input. The issue stems from… | |
| Analizada | Alta (8.8) | 2.6% | — | Huggingface Transformers | 22/11/2024 | 17/6/2026 | Hugging Face Transformers Trax Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must… | |
| Analizada | Alta (8.8) | 3.1% | — | Huggingface Transformers | 22/11/2024 | 17/6/2026 | Hugging Face Transformers MaskFormer Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target… | |
| Analizada | Alta (8.8) | 7.3% | — | Huggingface Transformers | 22/11/2024 | 17/6/2026 | Hugging Face Transformers MobileViTV2 Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must… | |
| Aplazada | Media (6.9) | 0.75% | — | Intel Extension FOR TransformersAI | 13/11/2024 | 17/6/2026 | Path traversal for some Intel(R) Extension for Transformers software before version 1.5 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Analizada | Crítica (9.6) | 2.1% | — | Huggingface Transformers | 10/4/2024 | 17/6/2026 | The huggingface/transformers library is vulnerable to arbitrary code execution through deserialization of untrusted data within the `load_repo_checkpoint()` function of the `TFPreTrainedModel()` class. Attackers can execute arbitrary code and commands by crafting a malicious serialized payload, exploiting the use of… | |
| Modificada | Alta (7.8) | 0.73% | — | Huggingface Transformers | 20/12/2023 | 17/6/2026 | Deserialization of Untrusted Data in GitHub repository huggingface/transformers prior to 4.36. | |
| Modificada | Alta (8.8) | 0.93% | — | Huggingface Transformers | 19/12/2023 | 17/6/2026 | Deserialization of Untrusted Data in GitHub repository huggingface/transformers prior to 4.36. | |
| Modificada | Media (4.7) | 0.29% | — | Huggingface Transformers | 18/5/2023 | 17/6/2026 | Insecure Temporary File in GitHub repository huggingface/transformers prior to 4.30.0. |