Transformers is vulnerable to ReDoS attack through its DonutProcessor class
        
  Moderate severity
        
          GitHub Reviewed
      
        Published
          Jul 11, 2025 
          to the GitHub Advisory Database
          •
          Updated Aug 7, 2025 
      
  
Description
        Published by the National Vulnerability Database
      Jul 11, 2025 
    
  
        Published to the GitHub Advisory Database
      Jul 11, 2025 
    
  
        Reviewed
      Jul 11, 2025 
    
  
        Last updated
      Aug 7, 2025 
    
  
A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically within the DonutProcessor class's
token2json()method. This vulnerability affects versions 4.51.3 and earlier, and is fixed in version 4.52.1. The issue arises from the regex pattern<s_(.*?)>which can be exploited to cause excessive CPU consumption through crafted input strings due to catastrophic backtracking. This vulnerability can lead to service disruption, resource exhaustion, and potential API service vulnerabilities, impacting document processing tasks using the Donut model.References