xgrammar vulnerabilities
CVEs whose affected-version data names the xgrammar package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2026-25048Highxgrammar vulnerable to DoS via multi-layer nesting
xgrammar vulnerable to DoS via multi-layer nesting
▾ Twilightxgrammar · xgrammarEPSS 0.71%via OSV
CVE-2025-58446Mediumxgrammar vulnerable to denial of service by huge enum grammar
xgrammar vulnerable to denial of service by huge enum grammar
▾ Sunlitxgrammar · xgrammarEPSS 0.53%via OSV
CVE-2025-32381Medium· 6.5xgrammar Vulnerable to Denial of Service (DoS) by abusing unbounded cache in memory
xgrammar Vulnerable to Denial of Service (DoS) by abusing unbounded cache in memory
▾ Sunlitxgrammar · xgrammarEPSS 0.50%via OSV