Newly released CVEs across every platform — sleek to read, verbose on demand, and served raw as markdown for AI and agent ingestion. Severity reads as depth: the deeper the contact, the graver the threat.
Depth = severity + exploitation
CVE-2026-9856High· 7.1A vulnerability in huggingface/transformers versions <=5.8.0.dev0 allows an attacker to perform arbitrary file writes via path traversal. The issue resides in the `save_pretrained()` methods of `PreTrainedTokenizerBase` and `ProcessorMix…
CVE-2026-4372High· 7.8HuggingFace transformers vulnerable to remote code execution
CVE-2026-1839Medium· 6.5HuggingFace Transformers allows for arbitrary code execution in the `Trainer` class
CVE-2025-6921Medium· 5.3Hugging Face Transformers vulnerable to Regular Expression Denial of Service (ReDoS) in the AdamWeightDecay optimizer
CVE-2025-6051Medium· 5.3Hugging Face Transformers library has Regular Expression Denial of Service
CVE-2025-6638Medium· 5.3Hugging Face Transformers is vulnerable to ReDoS through its MarianTokenizer
CVE-2025-5197Medium· 5.3Hugging Face Transformers Regular Expression Denial of Service (ReDoS) vulnerability
CVE-2025-3933Medium· 5.3Transformers is vulnerable to ReDoS attack through its DonutProcessor class
CVE-2025-3263Medium· 5.3Transformers's ReDoS vulnerability in get_configuration_file can lead to catastrophic backtracking
CVE-2025-3777Low· 3.5Transformers's Improper Input Validation vulnerability can be exploited through username injection
CVE-2025-3264Medium· 5.3Transformers vulnerable to ReDoS attack through its get_imports() function
CVE-2025-3262Medium· 5.3Transformers vulnerable to ReDoS attack through its SETTING_RE variable
CVE-2025-1194Medium· 4.3Transformers Regular Expression Denial of Service (ReDoS) vulnerability
CVE-2024-12720Medium· 5.3Transformers Regular Expression Denial of Service (ReDoS) vulnerability
CVE-2024-11393High· 8.80dayPoCDeserialization of Untrusted Data in Hugging Face Transformers
CVE-2024-11392High· 7.50dayPoCDeserialization of Untrusted Data in Hugging Face Transformers
CVE-2024-11394High· 8.80dayPoCDeserialization of Untrusted Data in Hugging Face Transformers
CVE-2024-3568Low· 3.4PoCTransformers Deserialization of Untrusted Data vulnerability
A summary of everything that shipped over the last two weeks — the whole corpus is open, agents get change feeds, alias resolution and EPSS movers, and the data now includes CVE.org, vendor CSAF, aggregated exploits and per-source scores.
A step-by-step guide to plugging VulnSea into automated and agentic workflows — poll the delta, triage without burning tokens, match an SBOM, and let an MCP-native model do the reasoning.
CVE and 0day intelligence that reads like an instrument — built for analysts and AI agents alike. Here's what it does and where it's going.