CVE-2024-12720
Transformers Regular Expression Denial of Service (ReDoS) vulnerability
5.3
MEDIUM
CVSS 3.1
EPSS 0.68%
描述
A Regular Expression Denial of Service (ReDoS) vulnerability was identified in the huggingface/transformers library, specifically in the file tokenization_nougat_fast.py. The vulnerability occurs in the post_process_single() function, where a regular expression processes specially crafted input. The issue stems from the regex exhibiting exponential time complexity under certain conditions, leading to excessive backtracking. This can result in significantly high CPU usage and potential application downtime, effectively creating a Denial of Service (DoS) scenario. The affected version is v4.46.3.
如何修補 CVE-2024-12720
要修補 CVE-2024-12720,請將受影響套件升級到下列已修補版本。
- —升級至 4.48.0 或更新版本
- —升級至 4.48.0 或更新版本
CVE-2024-12720 正在被利用嗎?
低 — EPSS 為 0.7%,目前沒有觀察到大規模利用活動。
受影響套件(2)
- from 0, < 4.48.0
- from 0, < 4.48.0
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.3 | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |