CVE-2025-57809High· 7.5▾ TwilightA flaw was found in xgrammar. Recursive grammar definitions could trigger infinite recursion during parsing in GrammarMatcherBase::ExpandEquivalentStackElements, leading to unbounded stack growth and a segmentation fault. This vulnerabilit…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.4%
0.4% → 0.5%
Last analysed / modified upstream
A flaw was found in xgrammar. Recursive grammar definitions could trigger infinite recursion during parsing in GrammarMatcherBase::ExpandEquivalentStackElements, leading to unbounded stack growth and a segmentation fault. This vulnerability allows remote attackers to cause a denial of service (DoS) when untrusted grammar is processed.
xgrammar: XGrammar affected by Denial of Service by infinite recursion grammars — rated Important by Red Hat. Released 2025-08-25, updated 2026-09-21.
Affected:
Fixed:
No fix planned:
For more information visit https://access.redhat.com/errata/RHSA-2025:19427 https://access.redhat.com/errata/RHSA-2025:19427 For more information visit https://access.redhat.com/errata/RHSA-2025:19429 https://access.redhat.com/errata/RHSA-2025:19429 For more information visit https://access.redhat.com/errata/RHSA-2025:19424 https://access.redhat.com/errata/RHSA-2025:19424
Workarounds / mitigations:
Affected packages:
xgrammar < 0.1.21Patched in:
xgrammar 0.1.21Connected by shared product, vendor, weakness, or advisory.
CVE-2026-81724High· 7.5nltk: NLTK: Denial of Service via Uncontrolled Recursion (CVE-2026-81724)
CVE-2026-73566High· 7.5node-tar is a tar archive manipulation library for Node.js
CVE-2026-77465High· 7.5toml-node is a TOML parser for Node.js and the browser
CVE-2026-59645High· 7.5In Bouncy Castle for Java before 1.85, OER parser recurses without depth limit on self-referential IEEE 1609.2 schema
CVE-2026-67313High· 7.5axios versions 0.28.0 and later contain uncontrolled recursion in formDataToJSON when processing FormData field names with deeply nested bracket segments
CVE-2026-67312High· 7.5axios versions from 0.28.0 before 0.33.0 and from 1.0.0 before 1.18.0 contain uncontrolled recursion in formDataToJSON (exposed as axios.formToJSON() and used internally when serializing FormData with Content-Type: application/json)