Database/AI/ML frameworks & serving
Hugging Face Transformers: ReDoS in the English number normalizer burns CPU on crafted input
Impact
normalize_numbers() in EnglishNormalizer handles numeric strings with a regex that degrades badly on long digit sequences, so a crafted request can pin a CPU core for far longer than the request is worth. This sits on the text-to-speech and number-normalization paths, which run in the request handler of an inference endpoint, so the cost lands on the serving process rather than on the caller. On a GPU node the practical effect is host-side starvation: the CPU workers that feed the accelerator stall, request queues back up and the GPU idles while the node still bills. Availability only - no data exposure and no code execution.
Who can reach it
Network, unauthenticated if the endpoint is public: anyone who can submit text to a service that routes through EnglishNormalizer (typically a TTS or text-normalization endpoint built on Transformers up to 4.52.4).
What to do
Upgrade Transformers to 4.53.0 or later and restart the serving processes - a dependency bump and a rolling restart of the inference workers, no node drain or reboot. Until then, cap input length and add a per-request CPU or wall-clock timeout in front of the normalizer.
References
Related entries
- BentoML OpenLLM 0.6.30 (async_run_command in src/openllm/common.py): A model repository directory name flows unescapedCVE-2026-15035 · BentoML OpenLLM 0.6.30 (async_run_command in src/openllm/common.py)Medium
- JupyterHub: unauthenticated logins write unbounded usernames to the log, exhausting storageCVE-2026-54338 · JupyterHub form-based login authenticators (failed-login logging)Medium
- vLLM: malformed JSON to the OpenAI-compatible endpoints returns server paths and versionsCVE-2026-73555 · vLLM OpenAI-compatible API server (validation_exception_handler, sanitize_message)Medium
- vLLM: attacker-supplied structured-output regex pins a CPU core and stalls the engine pathCVE-2026-73556 · vLLM structured outputs, lm-format-enforcer backend (structured_outputs.regex)Medium
- vLLM: integer overflow in the activation CUDA kernel leaks another batched request's outputCVE-2026-73558 · vLLM CUDA activation kernels (act_and_mul_kernel, activation_kernels.cu)Medium
- vLLM (DeepStream video backend, VideoMediaIO backend selection): A performance feature merged past two existingNCVD-2026-044-vllm-deepstream-video-backend-vi · vLLM (DeepStream video backend, VideoMediaIO backend selection)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.