Product
huggingface transformers
30 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-5241
CVE-2026-4372
CVE-2026-1839
CVE-2025-14930
CVE-2025-14929
CVE-2025-14928
CVE-2025-14927
CVE-2025-14926
CVE-2025-14924
CVE-2025-14921
CVE-2025-14920
CVE-2025-6921
CVE-2025-6051
CVE-2025-6638
CVE-2025-5197
CVE-2025-3933
CVE-2025-3777
CVE-2025-3264
CVE-2025-3263
CVE-2025-3262
CVE-2025-2099
CVE-2025-1194
CVE-2024-12720
CVE-2024-11394
CVE-2024-11393
CVE-2024-11392
CVE-2024-3568
CVE-2023-7018
CVE-2023-6730
CVE-2023-2800
all versions
A vulnerability in the LightGlue model loading path of huggingface/transformers version 5.2.0 allows an attacker-controlled model
< 5.3.0
A critical remote code execution vulnerability exists in all versions of the HuggingFace transformers library prior to version 5.3
< 5.0.0
A vulnerability in the HuggingFace Transformers library, specifically in the
Trainer class, allows for arbitrary code execution.all versions
Hugging Face Transformers GLM4 Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows re
all versions
Hugging Face Transformers X-CLIP Checkpoint Conversion Deserialization of Untrusted Data Remote Code Execution Vulnerability. This
all versions
Hugging Face Transformers HuBERT convert_config Code Injection Remote Code Execution Vulnerability. This vulnerability allows remo
all versions
Hugging Face Transformers SEW-D convert_config Code Injection Remote Code Execution Vulnerability. This vulnerability allows remot
all versions
Hugging Face Transformers SEW convert_config Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote
all versions
Hugging Face Transformers megatron_gpt2 Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability
all versions
Hugging Face Transformers Transformer-XL Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnera
all versions
Hugging Face Transformers Perceiver Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerabilit
< 4.53.0
The huggingface/transformers library, versions prior to 4.53.0, is vulnerable to Regular Expression Denial of Service (ReDoS) in t
all versions
A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically
all versions
A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically
< 4.53.0
A Regular Expression Denial of Service (ReDoS) vulnerability exists in the Hugging Face Transformers library, specifically in the
< 4.52.1
A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically
< 4.52.1
Hugging Face Transformers versions up to 4.49.0 are affected by an improper input validation vulnerability in the
image_utils.py>= 4.49.0 and < 4.51.0
A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically
>= 4.49.0 and < 4.51.0
A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically
< 4.51.0
A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the huggingface/transformers repository, specifical
<= 4.48.3
A vulnerability in the
preprocess_string() function of the transformers.testing_utils module in huggingface/transformers versi< 4.50.0
A Regular Expression Denial of Service (ReDoS) vulnerability was identified in the huggingface/transformers library, specifically
< 4.48.0
A Regular Expression Denial of Service (ReDoS) vulnerability was identified in the huggingface/transformers library, specifically
< 4.48.0
Hugging Face Transformers Trax Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability all
< 4.48.0
Hugging Face Transformers MaskFormer Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerabili
< 4.48.0
Hugging Face Transformers MobileViTV2 Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability al
< 4.38.0
The huggingface/transformers library is vulnerable to arbitrary code execution through deserialization of untrusted data within th
< 4.36.0
Deserialization of Untrusted Data in GitHub repository huggingface/transformers prior to 4.36.
< 4.36.0
Deserialization of Untrusted Data in GitHub repository huggingface/transformers prior to 4.36.
< 4.30.0
Insecure Temporary File in GitHub repository huggingface/transformers prior to 4.30.0.