CVE-2025-3933
A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically within the DonutProcessor class’s `token2json()` method. This vulnerability affects versions 4.50.3 and earlier, and is fixed in version 4.52.1. The issue arises from the regex pattern `
Assigner : security@huntr.dev
More information : https://github.com/huggingface/transformers/commit/ebbe9b12dd75b69f92100d684c47f923ee262a93