Vulnerabilities (CVE)

Filtered by vendor Mlc-ai
Angry Yack Logo
Total 3 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-58446 1 Mlc-ai 1 Xgrammar 2025-09-18 N/A 7.5 HIGH
xgrammar is an open-source library for efficient, flexible, and portable structured generation. A grammar optimizer introduced in 0.1.23 processes large grammars (>100k characters) at very low rates, and can be used for DOS of model providers. This issue is fixed in version 0.1.24.
CVE-2025-32381 1 Mlc-ai 1 Xgrammar 2025-09-17 N/A 6.5 MEDIUM
XGrammar is an open-source library for efficient, flexible, and portable structured generation. Prior to 0.1.18, Xgrammar includes a cache for compiled grammars to increase performance with repeated use of the same grammar. This cache is held in memory. Since the cache is unbounded, a system making use of xgrammar can be abused to fill up a host's memory and case a denial of service. For example, sending many small requests to an LLM inference server with unique JSON schemas would eventually cau ...

Show More

CVE-2025-57809 1 Mlc-ai 1 Xgrammar 2025-09-09 N/A 7.5 HIGH
XGrammar is an open-source library for efficient, flexible, and portable structured generation. Prior to version 0.1.21, XGrammar has an infinite recursion issue in the grammar. This issue has been resolved in version 0.1.21.