Skip to content

Commit 65ec1d2

Browse files
transformer fix (#5127)
* transformer fix * revert toml * update reason
1 parent aed9b73 commit 65ec1d2

File tree

4 files changed

+116
-0
lines changed

4 files changed

+116
-0
lines changed

autogluon/inference/docker/1.4/py3/Dockerfile.cpu.os_scan_allowlist.json

Lines changed: 29 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -382,6 +382,35 @@
382382
"status": "ACTIVE",
383383
"title": "CVE-2025-2099 - transformers",
384384
"reason_to_ignore": "Security vulnerability allowlisted for AutoGluon DLC"
385+
},
386+
{
387+
"description": "A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the huggingface/transformers repository, specifically in version 4.49.0. The vulnerability is due to inefficient regular expression complexity in the `SETTING_RE` variable within the `transformers/commands/chat.py` file. The regex contains repetition groups and non-optimized quantifiers, leading to exponential backtracking when processing 'almost matching' payloads. This can degrade application performance and potentially result in a denial-of-service (DoS) when handling specially crafted input strings. The issue is fixed in version 4.51.0.",
388+
"vulnerability_id": "CVE-2025-3262",
389+
"name": "CVE-2025-3262",
390+
"package_name": "transformers",
391+
"package_details": {
392+
"file_path": "/opt/conda/lib/python3.11/site-packages/transformers-4.49.0.dist-info/METADATA",
393+
"name": "transformers",
394+
"package_manager": "PYTHON",
395+
"version": "4.49.0",
396+
"release": null
397+
},
398+
"remediation": {
399+
"recommendation": {
400+
"text": "None Provided"
401+
}
402+
},
403+
"cvss_v3_score": 7.5,
404+
"cvss_v30_score": 0.0,
405+
"cvss_v31_score": 7.5,
406+
"cvss_v2_score": 0.0,
407+
"cvss_v3_severity": "HIGH",
408+
"source_url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3262",
409+
"source": "NVD",
410+
"severity": "HIGH",
411+
"status": "ACTIVE",
412+
"title": "CVE-2025-3262 - transformers",
413+
"reason_to_ignore": "No fix provided"
385414
}
386415
],
387416
"lightgbm": [

autogluon/inference/docker/1.4/py3/cu124/Dockerfile.gpu.os_scan_allowlist.json

Lines changed: 29 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -382,6 +382,35 @@
382382
"status": "ACTIVE",
383383
"title": "CVE-2025-2099 - transformers",
384384
"reason_to_ignore": "Security vulnerability allowlisted for AutoGluon DLC"
385+
},
386+
{
387+
"description": "A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the huggingface/transformers repository, specifically in version 4.49.0. The vulnerability is due to inefficient regular expression complexity in the `SETTING_RE` variable within the `transformers/commands/chat.py` file. The regex contains repetition groups and non-optimized quantifiers, leading to exponential backtracking when processing 'almost matching' payloads. This can degrade application performance and potentially result in a denial-of-service (DoS) when handling specially crafted input strings. The issue is fixed in version 4.51.0.",
388+
"vulnerability_id": "CVE-2025-3262",
389+
"name": "CVE-2025-3262",
390+
"package_name": "transformers",
391+
"package_details": {
392+
"file_path": "/opt/conda/lib/python3.11/site-packages/transformers-4.49.0.dist-info/METADATA",
393+
"name": "transformers",
394+
"package_manager": "PYTHON",
395+
"version": "4.49.0",
396+
"release": null
397+
},
398+
"remediation": {
399+
"recommendation": {
400+
"text": "None Provided"
401+
}
402+
},
403+
"cvss_v3_score": 7.5,
404+
"cvss_v30_score": 0.0,
405+
"cvss_v31_score": 7.5,
406+
"cvss_v2_score": 0.0,
407+
"cvss_v3_severity": "HIGH",
408+
"source_url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3262",
409+
"source": "NVD",
410+
"severity": "HIGH",
411+
"status": "ACTIVE",
412+
"title": "CVE-2025-3262 - transformers",
413+
"reason_to_ignore": "No fix provided"
385414
}
386415
],
387416
"lightgbm": [

autogluon/training/docker/1.4/py3/Dockerfile.cpu.os_scan_allowlist.json

Lines changed: 29 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -382,6 +382,35 @@
382382
"status": "ACTIVE",
383383
"title": "CVE-2025-2099 - transformers",
384384
"reason_to_ignore": "Security vulnerability allowlisted for AutoGluon DLC"
385+
},
386+
{
387+
"description": "A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the huggingface/transformers repository, specifically in version 4.49.0. The vulnerability is due to inefficient regular expression complexity in the `SETTING_RE` variable within the `transformers/commands/chat.py` file. The regex contains repetition groups and non-optimized quantifiers, leading to exponential backtracking when processing 'almost matching' payloads. This can degrade application performance and potentially result in a denial-of-service (DoS) when handling specially crafted input strings. The issue is fixed in version 4.51.0.",
388+
"vulnerability_id": "CVE-2025-3262",
389+
"name": "CVE-2025-3262",
390+
"package_name": "transformers",
391+
"package_details": {
392+
"file_path": "/opt/conda/lib/python3.11/site-packages/transformers-4.49.0.dist-info/METADATA",
393+
"name": "transformers",
394+
"package_manager": "PYTHON",
395+
"version": "4.49.0",
396+
"release": null
397+
},
398+
"remediation": {
399+
"recommendation": {
400+
"text": "None Provided"
401+
}
402+
},
403+
"cvss_v3_score": 7.5,
404+
"cvss_v30_score": 0.0,
405+
"cvss_v31_score": 7.5,
406+
"cvss_v2_score": 0.0,
407+
"cvss_v3_severity": "HIGH",
408+
"source_url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3262",
409+
"source": "NVD",
410+
"severity": "HIGH",
411+
"status": "ACTIVE",
412+
"title": "CVE-2025-3262 - transformers",
413+
"reason_to_ignore": "No fix provided"
385414
}
386415
],
387416
"lightgbm": [

autogluon/training/docker/1.4/py3/cu124/Dockerfile.gpu.os_scan_allowlist.json

Lines changed: 29 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -382,6 +382,35 @@
382382
"status": "ACTIVE",
383383
"title": "CVE-2025-2099 - transformers",
384384
"reason_to_ignore": "Security vulnerability allowlisted for AutoGluon DLC"
385+
},
386+
{
387+
"description": "A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the huggingface/transformers repository, specifically in version 4.49.0. The vulnerability is due to inefficient regular expression complexity in the `SETTING_RE` variable within the `transformers/commands/chat.py` file. The regex contains repetition groups and non-optimized quantifiers, leading to exponential backtracking when processing 'almost matching' payloads. This can degrade application performance and potentially result in a denial-of-service (DoS) when handling specially crafted input strings. The issue is fixed in version 4.51.0.",
388+
"vulnerability_id": "CVE-2025-3262",
389+
"name": "CVE-2025-3262",
390+
"package_name": "transformers",
391+
"package_details": {
392+
"file_path": "/opt/conda/lib/python3.11/site-packages/transformers-4.49.0.dist-info/METADATA",
393+
"name": "transformers",
394+
"package_manager": "PYTHON",
395+
"version": "4.49.0",
396+
"release": null
397+
},
398+
"remediation": {
399+
"recommendation": {
400+
"text": "None Provided"
401+
}
402+
},
403+
"cvss_v3_score": 7.5,
404+
"cvss_v30_score": 0.0,
405+
"cvss_v31_score": 7.5,
406+
"cvss_v2_score": 0.0,
407+
"cvss_v3_severity": "HIGH",
408+
"source_url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3262",
409+
"source": "NVD",
410+
"severity": "HIGH",
411+
"status": "ACTIVE",
412+
"title": "CVE-2025-3262 - transformers",
413+
"reason_to_ignore": "No fix provided"
385414
}
386415
],
387416
"lightgbm": [

0 commit comments

Comments
 (0)