CVE-2025-57809: XGrammar affected by Denial of Service by infinite recursion grammars
(updated )
This issue: http://github.com/mlc-ai/xgrammar/issues/250 should have it’s own security advisory. Since several tools accept and pass user supplied grammars to xgrammar, and it is so easy to trigger it seems like a High.
References
Code Behaviors & Features
Detect and mitigate CVE-2025-57809 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →