← signals
2026-07-27·HUGGINGFACE·devtool trust
meddown

On July 7, 2026, 12 distinct CVEs were published in the OSV database affecting the Hugging Face Transformers library,...

On July 7, 2026, 12 distinct CVEs were published in the OSV database affecting the Hugging Face Transformers library, including multiple ReDoS vulnerabilities, a deserialization flaw, and an input validation issue.

window 30devidence 87confidence score 100

confidence score

Strong evidence: 2 independent source classes support this read.

100
medium confidence2 independent source classesotherpasses publish gate

signal brief

On July 7, 2026, 12 distinct CVEs were published in the OSV database affecting the Hugging Face Transformers library, including multiple ReDoS vulnerabilities, a deserialization flaw, and an input validation issue. These advisories (PYSEC-2026-1977 through 1988) cover weaknesses in components like DonutProcessor, AdamWeightDecay optimizer, MarianTokenizer, and get_imports() function. The concentrated release of vulnerabilities suggests a security audit or increased scrutiny, potentially eroding developer trust in the core library maintained by Hugging Face.

What the sources said:

  • 'Transformers is vulnerable to ReDoS attack through its DonutProcessor class' (OSV advisory PYSEC-2026-1977)
  • 'Transformers Deserialization of Untrusted Data vulnerability' (PYSEC-2026-1978)
  • 'Hugging Face Transformers vulnerable to Regular Expression Denial of Service (ReDoS) in the AdamWeightDecay optimizer' (PYSEC-2026-1980)
  • 'Transformers's Improper Input Validation vulnerability can be exploited through username injection' (PYSEC-2026-1986)

These published flaws may prompt users to delay upgrades or seek alternatives, impacting Hugging Face's platform stickiness and ecosystem trust.

source data used

Decision support, not stock advice. This signal is research with cited evidence — not a recommendation to buy, sell, or hold any security.