<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 09 Oct 2026 10:08:51 +0000</lastBuildDate>
    <item>
      <title>certfr-2025-avi-0969 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0969</link>
      <description>certfr-2025-avi-0969</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0969</guid>
    </item>
    <item>
      <title>EUVD-2026-239951</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-239951</link>
      <description>EUVD-2026-239951</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-239951</guid>
    </item>
    <item>
      <title>fkie_cve-2025-2099</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-2099</link>
      <description>&lt;p&gt;A vulnerability in the `preprocess_string()` function of the `transformers.testing_utils` module in huggingface/transformers version v4.48.3 allows for a Regular Expression Denial of Service (ReDoS) attack. The regular expression used to process code blocks in docstrings contains nested quantifiers, leading to exponential backtracking when processing input with a large number of newline characters. An attacker can exploit this by providing a specially crafted payload, causing high CPU usage and potential application downtime, effectively resulting in a Denial of Service (DoS) scenario.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability in the `preprocess_string()` function of the `transformers.testing_utils` module in huggingface/transformers version v4.48.3 allows for a Regular Expression Denial of Service (ReDoS) attack. The regular expression used to process code blocks in docstrings contains nested quantifiers, leading to exponential backtracking when processing input with a large number of newline characters. An attacker can exploit this by providing a specially crafted payload, causing high CPU usage and potential application downtime, effectively resulting in a Denial of Service (DoS) scenario.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-2099</guid>
    </item>
    <item>
      <title>GHSA-qq3j-4f4f-9583 — Hugging Face Transformers Regular Expression Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-qq3j-4f4f-9583</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: transformers&lt;/p&gt;
&lt;p&gt;A Regular Expression Denial of Service (ReDoS) exists in the `preprocess_string()` function of the `transformers.testing_utils` module. In versions **before 4.50.0**, the regex used to process code blocks in docstrings contains nested quantifiers that can trigger catastrophic backtracking when given inputs with many newline characters. An attacker who can supply such input to `preprocess_string()` (or code paths that call it) can force excessive CPU usage and degrade availability.&lt;/p&gt;
&lt;p&gt;**Fix:** released in **4.50.0**, which rewrites the regex to avoid the inefficient pattern. ([GitHub][1])&lt;/p&gt;
&lt;p&gt;*   **Affected:** `&amp;lt; 4.50.0`
*   **Patched:** `4.50.0`&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: transformers&lt;/p&gt;
&lt;p&gt;A Regular Expression Denial of Service (ReDoS) exists in the `preprocess_string()` function of the `transformers.testing_utils` module. In versions **before 4.50.0**, the regex used to process code blocks in docstrings contains nested quantifiers that can trigger catastrophic backtracking when given inputs with many newline characters. An attacker who can supply such input to `preprocess_string()` (or code paths that call it) can force excessive CPU usage and degrade availability.&lt;/p&gt;
&lt;p&gt;**Fix:** released in **4.50.0**, which rewrites the regex to avoid the inefficient pattern. ([GitHub][1])&lt;/p&gt;
&lt;p&gt;*   **Affected:** `&amp;lt; 4.50.0`
*   **Patched:** `4.50.0`&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-qq3j-4f4f-9583</guid>
    </item>
    <item>
      <title>PYSEC-2025-40</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2025-40</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: transformers&lt;/p&gt;
&lt;p&gt;A vulnerability in the `preprocess_string()` function of the `transformers.testing_utils` module in huggingface/transformers version v4.48.3 allows for a Regular Expression Denial of Service (ReDoS) attack. The regular expression used to process code blocks in docstrings contains nested quantifiers, leading to exponential backtracking when processing input with a large number of newline characters. An attacker can exploit this by providing a specially crafted payload, causing high CPU usage and potential application downtime, effectively resulting in a Denial of Service (DoS) scenario.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: transformers&lt;/p&gt;
&lt;p&gt;A vulnerability in the `preprocess_string()` function of the `transformers.testing_utils` module in huggingface/transformers version v4.48.3 allows for a Regular Expression Denial of Service (ReDoS) attack. The regular expression used to process code blocks in docstrings contains nested quantifiers, leading to exponential backtracking when processing input with a large number of newline characters. An attacker can exploit this by providing a specially crafted payload, causing high CPU usage and potential application downtime, effectively resulting in a Denial of Service (DoS) scenario.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2025-40</guid>
    </item>
    <item>
      <title>RHSA-2025:12791 — Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.5 Container Release Update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:12791</link>
      <description>&lt;p&gt;transformers: Regular Expression Denial of Service (ReDoS) in huggingface/transformers&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;transformers: Regular Expression Denial of Service (ReDoS) in huggingface/transformers&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:12791</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-1707 — Red Hat Ansible Automation Platform: Schwachstelle ermöglicht Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1707</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat Ansible Automation Platform ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat Ansible Automation Platform ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1707</guid>
    </item>
  </channel>
</rss>
