{"id":"CVE-2025-32381","aliases":["GHSA-389x-67px-mjg3","PYSEC-2025-235"],"url":"https://o3.security/vulnerability/CVE-2025-32381","summary":"Denial of Service by abusing xgrammar unbounded cache in memory","details":"### Summary\n\nXgrammar includes a cache for compiled grammars to increase performance with repeated use of the same grammar. This cache is held in memory. Since the cache is unbounded, a system making use of xgrammar can be abused to fill up a host's memory and case a denial of service. For example, sending many small requests to an LLM inference server with unique JSON schemas would eventually cause this denial of service to occur.\n\n### Details\n\nThe fix is to add a limit to the cache size. This was done in https://github.com/mlc-ai/xgrammar/pull/243\n\nAn example of making use of the new cache size limit can be found in vLLM here: https://github.com/vllm-project/vllm/pull/16283\n\n### Impact\n\nAny system making use of Xgrammar and taking requests as input from potentially untrusted parties would be vulnerable to this denial of service issue.","published":"2025-04-09T16:00:10.642Z","modified":"2026-08-12T03:51:33.204483201Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"xgrammar","fixedVersion":"0.1.18"}],"fix":{"url":"https://github.com/mlc-ai/xgrammar/pull/243","label":"mlc-ai/xgrammar#243"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/32xxx/CVE-2025-32381.json"},{"type":"ADVISORY","url":"https://github.com/mlc-ai/xgrammar/security/advisories/GHSA-389x-67px-mjg3"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-32381"},{"type":"FIX","url":"https://github.com/mlc-ai/xgrammar/pull/243"},{"type":"FIX","url":"https://github.com/vllm-project/vllm/pull/16283"},{"type":"PACKAGE","url":"https://github.com/mlc-ai/xgrammar"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/xgrammar/PYSEC-2025-235.yaml"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:33.204483201Z"}}