{"id":"CVE-2025-57809","title":"xgrammar: XGrammar affected by Denial of Service by infinite recursion grammars (CVE-2025-57809)","summary":"A flaw was found in xgrammar. Recursive grammar definitions could trigger infinite recursion during parsing in GrammarMatcherBase::ExpandEquivalentStackElements, leading to unbounded stack growth and a segmentation fault. This vulnerabilit…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":"CWE-674","vendor":"Red Hat","product":"Red Hat Enterprise Linux AI 1.5","affected":["ai_inference_server","enterprise_linux_ai 1.5"],"patched":["enterprise_linux_ai 1.5"],"published":"2025-08-25","updated":"2026-09-21","sourceUpdated":"2026-09-21T15:58:24+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-57809.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-57809.json"},{"url":"https://access.redhat.com/security/cve/CVE-2025-57809"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2390943"},{"url":"https://www.cve.org/CVERecord?id=CVE-2025-57809"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-57809"},{"url":"https://github.com/mlc-ai/xgrammar/commit/b943feacb5a1caf4d39de8ec3bf7c7ce066dcee5"},{"url":"https://github.com/mlc-ai/xgrammar/issues/250"},{"url":"https://github.com/mlc-ai/xgrammar/security/advisories/GHSA-5cmr-4px5-23pc"},{"url":"https://access.redhat.com/errata/RHSA-2025:19427"},{"url":"https://access.redhat.com/errata/RHSA-2025:19429"},{"url":"https://access.redhat.com/errata/RHSA-2025:19424"},{"url":"https://access.redhat.com/errata/RHSA-2025:19430"},{"url":"https://access.redhat.com/errata/RHSA-2025:19426"},{"url":"https://access.redhat.com/errata/RHSA-2025:19422"},{"url":"https://access.redhat.com/errata/RHSA-2025:19428"},{"url":"https://access.redhat.com/errata/RHSA-2025:19425"},{"url":"https://access.redhat.com/errata/RHSA-2025:19421"},{"url":"https://access.redhat.com/errata/RHSA-2025:19423"},{"url":"https://github.com/mlc-ai/xgrammar"}],"tags":["csaf","vex","red-hat","osv","pip"],"epss":0.00466,"epssPercentile":0.39403,"aliases":["GHSA-5cmr-4px5-23pc","PYSEC-2026-2054"],"ecosystem":"pip","ingestedAt":"2026-07-08T18:25:45.969Z","slug":"CVE-2025-57809","body":"## Overview\n\nA flaw was found in xgrammar. Recursive grammar definitions could trigger infinite recursion during parsing in GrammarMatcherBase::ExpandEquivalentStackElements, leading to unbounded stack growth and a segmentation fault. This vulnerability allows remote attackers to cause a denial of service (DoS) when untrusted grammar is processed.\n\n## Vendor advisories\n\n- **RHSA-2025:19427** · Red Hat · fixed in: Red Hat Enterprise Linux AI 1.5 · released 2025-11-03 · [advisory](https://access.redhat.com/errata/RHSA-2025:19427)\n- **RHSA-2025:19429** · Red Hat · fixed in: Red Hat Enterprise Linux AI 1.5 · released 2025-11-03 · [advisory](https://access.redhat.com/errata/RHSA-2025:19429)\n- **RHSA-2025:19424** · Red Hat · fixed in: Red Hat Enterprise Linux AI 1.5 · released 2025-11-03 · [advisory](https://access.redhat.com/errata/RHSA-2025:19424)\n- **RHSA-2025:19430** · Red Hat · fixed in: Red Hat Enterprise Linux AI 1.5 · released 2025-11-03 · [advisory](https://access.redhat.com/errata/RHSA-2025:19430)\n- **RHSA-2025:19426** · Red Hat · fixed in: Red Hat Enterprise Linux AI 1.5 · released 2025-11-03 · [advisory](https://access.redhat.com/errata/RHSA-2025:19426)\n- **RHSA-2025:19422** · Red Hat · fixed in: Red Hat Enterprise Linux AI 1.5 · released 2025-11-03 · [advisory](https://access.redhat.com/errata/RHSA-2025:19422)\n- **RHSA-2025:19428** · Red Hat · fixed in: Red Hat Enterprise Linux AI 1.5 · released 2025-11-03 · [advisory](https://access.redhat.com/errata/RHSA-2025:19428)\n- **RHSA-2025:19425** · Red Hat · fixed in: Red Hat Enterprise Linux AI 1.5 · released 2025-11-03 · [advisory](https://access.redhat.com/errata/RHSA-2025:19425)\n- **RHSA-2025:19421** · Red Hat · fixed in: Red Hat Enterprise Linux AI 1.5 · released 2025-11-03 · [advisory](https://access.redhat.com/errata/RHSA-2025:19421)\n- **RHSA-2025:19423** · Red Hat · fixed in: Red Hat Enterprise Linux AI 1.5 · released 2025-11-03 · [advisory](https://access.redhat.com/errata/RHSA-2025:19423)\n- **Red Hat VEX** · Important · affected: Red Hat AI Inference Server · no fix planned: Red Hat AI Inference Server · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-57809.json)\n\n**xgrammar: XGrammar affected by Denial of Service by infinite recursion grammars** — rated Important by Red Hat. Released 2025-08-25, updated 2026-09-21.\n\nAffected:\n\n- Red Hat AI Inference Server\n\nFixed:\n\n- Red Hat Enterprise Linux AI 1.5\n\nNo fix planned:\n\n- Red Hat AI Inference Server\n\n## Remediation\n\nFor more information visit https://access.redhat.com/errata/RHSA-2025:19427 https://access.redhat.com/errata/RHSA-2025:19427\nFor more information visit https://access.redhat.com/errata/RHSA-2025:19429 https://access.redhat.com/errata/RHSA-2025:19429\nFor more information visit https://access.redhat.com/errata/RHSA-2025:19424 https://access.redhat.com/errata/RHSA-2025:19424\n\nWorkarounds / mitigations:\n\n- Mitigation is either unavailable or does not meet Red Hat Product Security standards for usability, deployment, applicability, or stability.\n\n## Package advisory (CVE-2025-57809)\n\nAffected packages:\n\n- `xgrammar < 0.1.21`\n\nPatched in:\n\n- `xgrammar 0.1.21`\n\nSource: https://osv.dev/vulnerability/GHSA-5cmr-4px5-23pc","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}