CVE-2025-58446

HIGH

xgrammar <0.1.23 - DoS

Title source: llm
STIX 2.1

Description

xgrammar is an open-source library for efficient, flexible, and portable structured generation. A grammar optimizer introduced in 0.1.23 processes large grammars (>100k characters) at very low rates, and can be used for DOS of model providers. This issue is fixed in version 0.1.24.

Scores

CVSS v3 7.5
EPSS 0.0010
EPSS Percentile 27.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-770
Status published
Products (2)
mlc-ai/xgrammar 0.1.23
pypi/xgrammar 0.1.23 - 0.1.24PyPI
Published Sep 06, 2025
Tracked Since Feb 18, 2026