← signals
2026-07-20·HUGGINGFACE·security risk
meddown

On July 7, 2026, 11 CVEs were published against the Hugging Face Transformers library, including multiple Regular...

On July 7, 2026, 11 CVEs were published against the Hugging Face Transformers library, including multiple Regular Expression Denial of Service (ReDoS) vulnerabilities and a deserialization issue.

window 30devidence 88confidence score 100

confidence score

Strong evidence: 3 independent source classes support this read.

100
medium confidence3 independent source classesotherpasses publish gate

signal brief

On July 7, 2026, 11 CVEs were published against the Hugging Face Transformers library, including multiple Regular Expression Denial of Service (ReDoS) vulnerabilities and a deserialization issue. These advisories (e.g., CVE-2025-3933, CVE-2024-3568, CVE-2025-3262) affect core components including DonutProcessor, tokenizers, and optimizer classes. The cluster of vulnerabilities suggests a systemic security weakness in the library's input validation, which could be exploited to cause service disruption or remote code execution in downstream AI applications. A new version 5.14.1 was released on July 16 (PyPI), likely containing fixes, but adoption takes time. Enterprises using Transformers for inference pipelines face increased operational risk until patching is complete.

What the sources said:

  • 'Transformers is vulnerable to ReDoS attack through its DonutProcessor class' (PYSEC-2026-1977).
  • 'Transformers Deserialization of Untrusted Data vulnerability' (PYSEC-2026-1978).
  • 'Hugging Face Transformers vulnerable to ReDoS through its MarianTokenizer' (PYSEC-2026-1981).
  • 'Hugging Face Transformers library has Regular Expression Denial of Service' (PYSEC-2026-1988).

source data used

Decision support, not stock advice. This signal is research with cited evidence — not a recommendation to buy, sell, or hold any security.