GPU VulnDB

Database/AI/ML frameworks & serving

Hugging Face Transformers: ReDoS in the English number normalizer burns CPU on crafted input

CVSS 5.3CVE-2025-6051AI/ML frameworks & servingcurated

Impact

normalize_numbers() in EnglishNormalizer handles numeric strings with a regex that degrades badly on long digit sequences, so a crafted request can pin a CPU core for far longer than the request is worth. This sits on the text-to-speech and number-normalization paths, which run in the request handler of an inference endpoint, so the cost lands on the serving process rather than on the caller. On a GPU node the practical effect is host-side starvation: the CPU workers that feed the accelerator stall, request queues back up and the GPU idles while the node still bills. Availability only - no data exposure and no code execution.

Who can reach it

Network, unauthenticated if the endpoint is public: anyone who can submit text to a service that routes through EnglishNormalizer (typically a TTS or text-normalization endpoint built on Transformers up to 4.52.4).

What to do

Upgrade Transformers to 4.53.0 or later and restart the serving processes - a dependency bump and a rolling restart of the inference workers, no node drain or reboot. Until then, cap input length and add a per-request CPU or wall-clock timeout in front of the normalizer.

References

Related entries

All AI/ML frameworks & serving entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.