{"schema_version":1,"title":"transformers (PyPI) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 31 vulnerabilities in transformers (PyPI): 0 in the last 7 days and 13 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-9856, was published on 2 August 2026.","url":"https://junglewise.ai/threats/technologies/pypi-transformers","json_url":"https://junglewise.ai/threats/technologies/pypi-transformers.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/pypi-transformers","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":6,"all_time":31,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":13,"last_365_days":24},"latest":[{"cve":"CVE-2026-9856","cvss":7.1,"epss":0.0046,"slug":"cve-2026-9856-hugging-face-transformers-path-traversal-in-save-pretrained","title":"A vulnerability in huggingface/transformers versions <=5.8.0.dev0 allows an attacker to perform arbitrary file writes via path traversal. Th","severity":"high","exploited":false,"published_at":"2026-08-02T16:16:25.413+00:00","url":"https://junglewise.ai/threats/cve-2026-9856-hugging-face-transformers-path-traversal-in-save-pretrained"},{"cve":"CVE-2025-6921","cvss":3,"epss":0.0051,"slug":"cve-2025-6921-hugging-face-transformers-vulnerable-to-regular-expression-denial","title":"PYSEC-2026-1980 - Hugging Face Transformers vulnerable to Regular Expression Denial of Service (ReDoS) in the AdamWeightDecay optimizer","severity":"low","exploited":false,"published_at":"2026-07-07T16:03:05.256373+00:00","url":"https://junglewise.ai/threats/cve-2025-6921-hugging-face-transformers-vulnerable-to-regular-expression-denial"},{"cve":"CVE-2025-6051","cvss":3,"epss":0.0038,"slug":"cve-2025-6051-hugging-face-transformers-library-has-regular-expression-denial-of","title":"PYSEC-2026-1988 - Hugging Face Transformers library has Regular Expression Denial of Service","severity":"low","exploited":false,"published_at":"2026-07-07T16:03:05.05241+00:00","url":"https://junglewise.ai/threats/cve-2025-6051-hugging-face-transformers-library-has-regular-expression-denial-of"},{"cve":"CVE-2025-6638","cvss":3,"epss":0.0053,"slug":"cve-2025-6638-hugging-face-transformers-is-vulnerable-to-redos-through-its","title":"PYSEC-2026-1981 - Hugging Face Transformers is vulnerable to ReDoS through its MarianTokenizer","severity":"low","exploited":false,"published_at":"2026-07-07T16:03:04.965561+00:00","url":"https://junglewise.ai/threats/cve-2025-6638-hugging-face-transformers-is-vulnerable-to-redos-through-its"},{"cve":"CVE-2025-5197","cvss":3,"epss":0.004,"slug":"cve-2025-5197-hugging-face-transformers-regular-expression-denial-of-service","title":"PYSEC-2026-1983 - Hugging Face Transformers Regular Expression Denial of Service (ReDoS) vulnerability","severity":"low","exploited":false,"published_at":"2026-07-07T16:03:00.318313+00:00","url":"https://junglewise.ai/threats/cve-2025-5197-hugging-face-transformers-regular-expression-denial-of-service"},{"cve":"CVE-2025-3933","cvss":3.1,"epss":0.0044,"slug":"cve-2025-3933-hugging-face-transformers-redos-in-donutprocessor","title":"PYSEC-2026-1977 - Transformers is vulnerable to ReDoS attack through its DonutProcessor class","severity":"low","exploited":false,"published_at":"2026-07-07T16:02:57.564922+00:00","url":"https://junglewise.ai/threats/cve-2025-3933-hugging-face-transformers-redos-in-donutprocessor"},{"cve":"CVE-2025-3263","cvss":3,"epss":0.0044,"slug":"cve-2025-3263-transformers-s-redos-vulnerability-in-get-configuration-file-can","title":"PYSEC-2026-1987 - Transformers's ReDoS vulnerability in get_configuration_file can lead to catastrophic backtracking","severity":"low","exploited":false,"published_at":"2026-07-07T16:02:56.8165+00:00","url":"https://junglewise.ai/threats/cve-2025-3263-transformers-s-redos-vulnerability-in-get-configuration-file-can"},{"cve":"CVE-2025-3262","cvss":3.1,"epss":0.0043,"slug":"cve-2025-3262-transformers-vulnerable-to-redos-attack-through-its-setting-re","title":"PYSEC-2026-1979 - Transformers vulnerable to ReDoS attack through its SETTING_RE variable","severity":"low","exploited":false,"published_at":"2026-07-07T16:02:56.726858+00:00","url":"https://junglewise.ai/threats/cve-2025-3262-transformers-vulnerable-to-redos-attack-through-its-setting-re"},{"cve":"CVE-2025-3777","cvss":3,"epss":0.0036,"slug":"cve-2025-3777-transformers-s-improper-input-validation-vulnerability-can-be","title":"PYSEC-2026-1986 - Transformers's Improper Input Validation vulnerability can be exploited through username injection","severity":"low","exploited":false,"published_at":"2026-07-07T16:02:56.629377+00:00","url":"https://junglewise.ai/threats/cve-2025-3777-transformers-s-improper-input-validation-vulnerability-can-be"},{"cve":"CVE-2025-3264","cvss":3,"epss":0.0044,"slug":"cve-2025-3264-transformers-vulnerable-to-redos-attack-through-its-get-imports","title":"PYSEC-2026-1985 - Transformers vulnerable to ReDoS attack through its get_imports() function","severity":"low","exploited":false,"published_at":"2026-07-07T16:02:56.404197+00:00","url":"https://junglewise.ai/threats/cve-2025-3264-transformers-vulnerable-to-redos-attack-through-its-get-imports"},{"cve":"CVE-2025-1194","cvss":3.1,"epss":0.0048,"slug":"cve-2025-1194-transformers-regular-expression-denial-of-service-redos","title":"PYSEC-2026-1984 - Transformers Regular Expression Denial of Service (ReDoS) vulnerability","severity":"low","exploited":false,"published_at":"2026-07-07T16:02:51.553781+00:00","url":"https://junglewise.ai/threats/cve-2025-1194-transformers-regular-expression-denial-of-service-redos"},{"cve":"CVE-2024-12720","cvss":3,"epss":0.0073,"slug":"cve-2024-12720-transformers-regular-expression-denial-of-service-redos","title":"PYSEC-2026-1982 - Transformers Regular Expression Denial of Service (ReDoS) vulnerability","severity":"low","exploited":false,"published_at":"2026-07-07T14:34:53.085416+00:00","url":"https://junglewise.ai/threats/cve-2024-12720-transformers-regular-expression-denial-of-service-redos"},{"cve":"CVE-2024-3568","cvss":3,"epss":0.0208,"slug":"cve-2024-3568-hugging-face-transformers-deserialization-of-untrusted-data","title":"PYSEC-2026-1978 - Transformers Deserialization of Untrusted Data vulnerability","severity":"low","exploited":false,"published_at":"2026-07-07T11:45:37.939935+00:00","url":"https://junglewise.ai/threats/cve-2024-3568-hugging-face-transformers-deserialization-of-untrusted-data"},{"cve":"CVE-2026-5241","cvss":8,"epss":0.0094,"slug":"cve-2026-5241-hugging-face-transformers-rce-in-lightglue-model-loading","title":"Hugging Face Transformers RCE in LightGlue model loading","severity":"high","exploited":false,"published_at":"2026-06-03T14:16:46.337+00:00","url":"https://junglewise.ai/threats/cve-2026-5241-hugging-face-transformers-rce-in-lightglue-model-loading"},{"cve":"CVE-2026-4372","cvss":7.8,"epss":0.006,"slug":"cve-2026-4372-huggingface-transformers-remote-code-execution-via-config-json","title":"HuggingFace transformers remote code execution via config.json","severity":"high","exploited":false,"published_at":"2026-05-24T14:16:16.917+00:00","url":"https://junglewise.ai/threats/cve-2026-4372-huggingface-transformers-remote-code-execution-via-config-json"},{"cve":"CVE-2026-1839","cvss":3.1,"epss":0.0038,"slug":"cve-2026-1839-huggingface-transformers-allows-for-arbitrary-code-execution-in","title":"PYSEC-2026-2288 - A vulnerability in the HuggingFace Transformers library, specifically in the `Trainer` class, allows for arbitrary code execution. The `_loa","severity":"low","exploited":false,"published_at":"2026-04-07T06:16:41.49+00:00","url":"https://junglewise.ai/threats/cve-2026-1839-huggingface-transformers-allows-for-arbitrary-code-execution-in"},{"cve":"CVE-2025-14930","cvss":3,"epss":0.0033,"slug":"cve-2025-14930-pysec-2025-218-hugging-face-transformers-glm4-deserialization-of","title":"PYSEC-2025-218 - Hugging Face Transformers GLM4 Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attac","severity":"low","exploited":false,"published_at":"2025-12-23T21:15:48.367+00:00","url":"https://junglewise.ai/threats/cve-2025-14930-pysec-2025-218-hugging-face-transformers-glm4-deserialization-of"},{"cve":"CVE-2025-14929","cvss":3,"epss":0.0037,"slug":"cve-2025-14929-pysec-2025-217-hugging-face-transformers-x-clip-checkpoint","title":"PYSEC-2025-217 - Hugging Face Transformers X-CLIP Checkpoint Conversion Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerabi","severity":"low","exploited":false,"published_at":"2025-12-23T21:15:48.24+00:00","url":"https://junglewise.ai/threats/cve-2025-14929-pysec-2025-217-hugging-face-transformers-x-clip-checkpoint"},{"cve":"CVE-2025-14928","cvss":3,"epss":0.0034,"slug":"cve-2025-14928-pysec-2025-216-hugging-face-transformers-hubert-convert-config","title":"PYSEC-2025-216 - Hugging Face Transformers HuBERT convert_config Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attacke","severity":"low","exploited":false,"published_at":"2025-12-23T21:15:48.11+00:00","url":"https://junglewise.ai/threats/cve-2025-14928-pysec-2025-216-hugging-face-transformers-hubert-convert-config"},{"cve":"CVE-2025-14927","cvss":3,"epss":0.0034,"slug":"cve-2025-14927-pysec-2025-215-hugging-face-transformers-sew-d-convert-config","title":"PYSEC-2025-215 - Hugging Face Transformers SEW-D convert_config Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attacker","severity":"low","exploited":false,"published_at":"2025-12-23T21:15:47.987+00:00","url":"https://junglewise.ai/threats/cve-2025-14927-pysec-2025-215-hugging-face-transformers-sew-d-convert-config"},{"cve":"CVE-2025-14926","cvss":3,"epss":0.0034,"slug":"cve-2025-14926-pysec-2025-214-hugging-face-transformers-sew-convert-config-code","title":"PYSEC-2025-214 - Hugging Face Transformers SEW convert_config Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers","severity":"low","exploited":false,"published_at":"2025-12-23T21:15:47.857+00:00","url":"https://junglewise.ai/threats/cve-2025-14926-pysec-2025-214-hugging-face-transformers-sew-convert-config-code"},{"cve":"CVE-2025-14924","cvss":3,"epss":0.0033,"slug":"cve-2025-14924-pysec-2025-213-hugging-face-transformers-megatron-gpt2","title":"PYSEC-2025-213 - Hugging Face Transformers megatron_gpt2 Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows rem","severity":"low","exploited":false,"published_at":"2025-12-23T21:15:47.6+00:00","url":"https://junglewise.ai/threats/cve-2025-14924-pysec-2025-213-hugging-face-transformers-megatron-gpt2"},{"cve":"CVE-2025-14921","cvss":3,"epss":0.0033,"slug":"cve-2025-14921-pysec-2025-212-hugging-face-transformers-transformer-xl-model","title":"PYSEC-2025-212 - Hugging Face Transformers Transformer-XL Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability all","severity":"low","exploited":false,"published_at":"2025-12-23T21:15:47.34+00:00","url":"https://junglewise.ai/threats/cve-2025-14921-pysec-2025-212-hugging-face-transformers-transformer-xl-model"},{"cve":"CVE-2025-14920","cvss":3,"epss":0.0036,"slug":"cve-2025-14920-pysec-2025-211-hugging-face-transformers-perceiver-model","title":"PYSEC-2025-211 - Hugging Face Transformers Perceiver Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows r","severity":"low","exploited":false,"published_at":"2025-12-23T21:15:47.183+00:00","url":"https://junglewise.ai/threats/cve-2025-14920-pysec-2025-211-hugging-face-transformers-perceiver-model"},{"cve":"CVE-2025-2099","cvss":3.1,"epss":0.0058,"slug":"cve-2025-2099-hugging-face-transformers-regular-expression-denial-of-service","title":"PYSEC-2025-40 - A vulnerability in the `preprocess_string()` function of the `transformers.testing_utils` module in huggingface/transformers version v4.48.3","severity":"low","exploited":false,"published_at":"2025-05-19T12:15:19+00:00","url":"https://junglewise.ai/threats/cve-2025-2099-hugging-face-transformers-regular-expression-denial-of-service"}],"weekly":[{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":12},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-28","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"tensorflow (PyPI)","slug":"pypi-tensorflow","vulnerabilities":428,"url":"https://junglewise.ai/threats/technologies/pypi-tensorflow"},{"name":"tensorflow-cpu (PyPI)","slug":"tensorflow-cpu","vulnerabilities":424,"url":"https://junglewise.ai/threats/technologies/tensorflow-cpu"},{"name":"tensorflow-gpu (PyPI)","slug":"tensorflow-gpu","vulnerabilities":421,"url":"https://junglewise.ai/threats/technologies/tensorflow-gpu"},{"name":"open-webui (PyPI)","slug":"open-webui","vulnerabilities":177,"url":"https://junglewise.ai/threats/technologies/open-webui"},{"name":"Django (PyPI)","slug":"django","vulnerabilities":172,"url":"https://junglewise.ai/threats/technologies/django"},{"name":"apache-airflow (PyPI)","slug":"apache-airflow","vulnerabilities":152,"url":"https://junglewise.ai/threats/technologies/apache-airflow"},{"name":"plone (PyPI)","slug":"pypi-plone","vulnerabilities":101,"url":"https://junglewise.ai/threats/technologies/pypi-plone"},{"name":"praisonai (PyPI)","slug":"pypi-praisonai","vulnerabilities":86,"url":"https://junglewise.ai/threats/technologies/pypi-praisonai"},{"name":"exiv2 (PyPI)","slug":"exiv2","vulnerabilities":85,"url":"https://junglewise.ai/threats/technologies/exiv2"},{"name":"nltk (PyPI)","slug":"nltk","vulnerabilities":83,"url":"https://junglewise.ai/threats/technologies/nltk"},{"name":"mlflow (PyPI)","slug":"mlflow","vulnerabilities":82,"url":"https://junglewise.ai/threats/technologies/mlflow"},{"name":"pillow (PyPI)","slug":"pillow","vulnerabilities":79,"url":"https://junglewise.ai/threats/technologies/pillow"}],"technology":{"hub":true,"name":"transformers (PyPI)","slug":"pypi-transformers","vendor":{"name":"PyPI","slug":"pypi","url":"https://junglewise.ai/threats/vendors/pypi"},"aliases":[],"description":"Python library providing pre-trained transformer models for natural language processing tasks.","url":"https://junglewise.ai/threats/technologies/pypi-transformers"},"most_severe":[{"cve":"CVE-2024-11393","cvss":8.8,"epss":0.0307,"slug":"cve-2024-11393-hugging-face-transformers-deserialization-of-untrusted-data-in","title":"Hugging Face Transformers deserialization of untrusted data in model parsing","severity":"high","exploited":false,"published_at":"2024-11-23T03:31:58+00:00","url":"https://junglewise.ai/threats/cve-2024-11393-hugging-face-transformers-deserialization-of-untrusted-data-in"},{"cve":"CVE-2024-11394","cvss":8.8,"epss":0.0257,"slug":"cve-2024-11394-hugging-face-transformers-deserialization-of-untrusted-data-in","title":"Hugging Face Transformers deserialization of untrusted data in model files","severity":"high","exploited":false,"published_at":"2024-11-23T03:31:58+00:00","url":"https://junglewise.ai/threats/cve-2024-11394-hugging-face-transformers-deserialization-of-untrusted-data-in"},{"cve":"CVE-2026-5241","cvss":8,"epss":0.0094,"slug":"cve-2026-5241-hugging-face-transformers-rce-in-lightglue-model-loading","title":"Hugging Face Transformers RCE in LightGlue model loading","severity":"high","exploited":false,"published_at":"2026-06-03T14:16:46.337+00:00","url":"https://junglewise.ai/threats/cve-2026-5241-hugging-face-transformers-rce-in-lightglue-model-loading"},{"cve":"CVE-2026-4372","cvss":7.8,"epss":0.006,"slug":"cve-2026-4372-huggingface-transformers-remote-code-execution-via-config-json","title":"HuggingFace transformers remote code execution via config.json","severity":"high","exploited":false,"published_at":"2026-05-24T14:16:16.917+00:00","url":"https://junglewise.ai/threats/cve-2026-4372-huggingface-transformers-remote-code-execution-via-config-json"},{"cve":"CVE-2024-11392","cvss":7.5,"epss":0.0726,"slug":"cve-2024-11392-hugging-face-transformers-deserialization-of-untrusted-data-in","title":"Hugging Face Transformers deserialization of untrusted data in config handling","severity":"high","exploited":false,"published_at":"2024-11-23T03:31:58+00:00","url":"https://junglewise.ai/threats/cve-2024-11392-hugging-face-transformers-deserialization-of-untrusted-data-in"},{"cve":"CVE-2026-9856","cvss":7.1,"epss":0.0046,"slug":"cve-2026-9856-hugging-face-transformers-path-traversal-in-save-pretrained","title":"A vulnerability in huggingface/transformers versions <=5.8.0.dev0 allows an attacker to perform arbitrary file writes via path traversal. Th","severity":"high","exploited":false,"published_at":"2026-08-02T16:16:25.413+00:00","url":"https://junglewise.ai/threats/cve-2026-9856-hugging-face-transformers-path-traversal-in-save-pretrained"},{"cve":"CVE-2023-6730","cvss":3.1,"epss":0.0093,"slug":"cve-2023-6730-hugging-face-transformers-deserialization-of-untrusted-data","title":"PYSEC-2023-300 - Deserialization of Untrusted Data in GitHub repository huggingface/transformers prior to 4.36.","severity":"low","exploited":false,"published_at":"2023-12-19T13:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-6730-hugging-face-transformers-deserialization-of-untrusted-data"},{"cve":"CVE-2023-7018","cvss":3.1,"epss":0.0073,"slug":"cve-2023-7018-transformers-has-a-deserialization-of-untrusted-data-vulnerability","title":"PYSEC-2023-301 - Deserialization of Untrusted Data in GitHub repository huggingface/transformers prior to 4.36.","severity":"low","exploited":false,"published_at":"2023-12-20T17:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-7018-transformers-has-a-deserialization-of-untrusted-data-vulnerability"},{"cve":"CVE-2025-2099","cvss":3.1,"epss":0.0058,"slug":"cve-2025-2099-hugging-face-transformers-regular-expression-denial-of-service","title":"PYSEC-2025-40 - A vulnerability in the `preprocess_string()` function of the `transformers.testing_utils` module in huggingface/transformers version v4.48.3","severity":"low","exploited":false,"published_at":"2025-05-19T12:15:19+00:00","url":"https://junglewise.ai/threats/cve-2025-2099-hugging-face-transformers-regular-expression-denial-of-service"},{"cve":"CVE-2025-1194","cvss":3.1,"epss":0.0048,"slug":"cve-2025-1194-transformers-regular-expression-denial-of-service-redos","title":"PYSEC-2026-1984 - Transformers Regular Expression Denial of Service (ReDoS) vulnerability","severity":"low","exploited":false,"published_at":"2026-07-07T16:02:51.553781+00:00","url":"https://junglewise.ai/threats/cve-2025-1194-transformers-regular-expression-denial-of-service-redos"}],"generated_at":"2026-09-28T03:07:00.154823+00:00"}