CVE Vulnerabilities

CVE-2025-57809

Uncontrolled Recursion

Published: Aug 25, 2025 | Modified: Sep 09, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
7.5 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
root.io logo minimus.io logo echo.ai logo

XGrammar is an open-source library for efficient, flexible, and portable structured generation. Prior to version 0.1.21, XGrammar has an infinite recursion issue in the grammar. This issue has been resolved in version 0.1.21.

Weakness

The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.

Affected Software

NameVendorStart VersionEnd Version
XgrammarMlc-ai*0.1.21 (excluding)
Red Hat Enterprise Linux AI 1.5RedHatrhelai1/instructlab-intel-rhel9:sha256:cf0ec4ad1520ff2ce83420846830286e036f310f880cf8a533f0966c35ebd32f*
Red Hat Enterprise Linux AI 1.5RedHatrhelai1/bootc-intel-rhel9:sha256:601064840ac29ea7d4a977efb506df226a2931d5079ec9f432bdf60095bf7c2e*
Red Hat Enterprise Linux AI 1.5RedHatrhelai1/instructlab-nvidia-rhel9:sha256:a17f53b6c19150fce3e6d456fde71a74bdab5da5eeb44bec7791084c3471a98e*
Red Hat Enterprise Linux AI 1.5RedHatrhelai1/bootc-azure-amd-rhel9:sha256:f77167ea53b46b91631679ed84aab2373ff56dc62cba946296be212443bc2a99*
Red Hat Enterprise Linux AI 1.5RedHatrhelai1/instructlab-amd-rhel9:sha256:03f22e965af16fe84aed7d30e7b8db00dead11d9fd4b11e3c9abb2e68dd910f1*
Red Hat Enterprise Linux AI 1.5RedHatrhelai1/bootc-gcp-nvidia-rhel9:sha256:a83229f005c78e271c774f3eda26421fedbc4b8cf1ac3fe94234899c6d677124*
Red Hat Enterprise Linux AI 1.5RedHatrhelai1/bootc-amd-rhel9:sha256:c029b66a3354ee6fd186a1f05aff31b5834e611b9d5b326b65b16829d6b98d1f*
Red Hat Enterprise Linux AI 1.5RedHatrhelai1/bootc-nvidia-rhel9:sha256:0efbdee5f2ec93477b5aac5dd4c1dd9b31fe96e5e7c7dd701738ceaa86b2f2eb*
Red Hat Enterprise Linux AI 1.5RedHatrhelai1/bootc-aws-nvidia-rhel9:sha256:385028a96717418982de197f8f0a9052edf12f80a50bd8ab53ca72203a4ba5d8*
Red Hat Enterprise Linux AI 1.5RedHatrhelai1/bootc-azure-nvidia-rhel9:sha256:427596ae2591a30a0218b7cfdd858ccad96178ddc2618cdf0a6e4e9af36685bf*

Potential Mitigations

References