{"id":"CVE-2025-57809","aliases":["GHSA-5cmr-4px5-23pc","PYSEC-2026-2054"],"url":"https://o3.security/vulnerability/CVE-2025-57809","summary":"XGrammar affected by Denial of Service by infinite recursion grammars","details":"### Summary\nThis issue: http://github.com/mlc-ai/xgrammar/issues/250 should have it's own security advisory. Since several tools accept and pass user supplied grammars to xgrammar, and it is so easy to trigger it seems like a High.","published":"2025-08-25T21:22:00.226Z","modified":"2026-08-12T15:16:51.222485Z","cvss":null,"epss":{"score":0.00462,"percentile":0.37973,"asOf":"2026-08-13"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"xgrammar","fixedVersion":"0.1.21"}],"fix":{"url":"https://github.com/mlc-ai/xgrammar/commit/b943feacb5a1caf4d39de8ec3bf7c7ce066dcee5","label":"mlc-ai/xgrammar@b943fea"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/57xxx/CVE-2025-57809.json"},{"type":"ADVISORY","url":"https://github.com/mlc-ai/xgrammar/security/advisories/GHSA-5cmr-4px5-23pc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-57809"},{"type":"REPORT","url":"https://github.com/mlc-ai/xgrammar/issues/250"},{"type":"FIX","url":"https://github.com/mlc-ai/xgrammar/commit/b943feacb5a1caf4d39de8ec3bf7c7ce066dcee5"},{"type":"PACKAGE","url":"https://github.com/mlc-ai/xgrammar"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T15:16:51.222485Z"}}