{"id":"CVE-2025-57809","aliases":["GHSA-5cmr-4px5-23pc","PYSEC-2026-2054"],"url":"https://o3.security/vulnerability/CVE-2025-57809","summary":"XGrammar affected by Denial of Service by infinite recursion grammars","details":"XGrammar is an open-source library for efficient, flexible, and portable structured generation. Prior to version 0.1.21, XGrammar has an infinite recursion issue in the grammar. This issue has been resolved in version 0.1.21.","published":"2025-08-25T21:22:00.226Z","modified":"2026-08-07T08:12:10.832141387Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"xgrammar","fixedVersion":"0.1.21"}],"fix":{"url":"https://github.com/mlc-ai/xgrammar/commit/b943feacb5a1caf4d39de8ec3bf7c7ce066dcee5","label":"mlc-ai/xgrammar@b943fea"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/57xxx/CVE-2025-57809.json"},{"type":"ADVISORY","url":"https://github.com/mlc-ai/xgrammar/security/advisories/GHSA-5cmr-4px5-23pc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-57809"},{"type":"REPORT","url":"https://github.com/mlc-ai/xgrammar/issues/250"},{"type":"FIX","url":"https://github.com/mlc-ai/xgrammar/commit/b943feacb5a1caf4d39de8ec3bf7c7ce066dcee5"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T08:12:10.832141387Z"}}