XGrammar affected by Denial of Service by infinite recursion grammars
Description
Published to the GitHub Advisory Database
Aug 25, 2025
Reviewed
Aug 25, 2025
Published by the National Vulnerability Database
Aug 25, 2025
Last updated
Sep 10, 2025
Summary
This issue: http://github.com/mlc-ai/xgrammar/issues/250 should have it's own security advisory. Since several tools accept and pass user supplied grammars to xgrammar, and it is so easy to trigger it seems like a High.
References