CVE-2025-58446: Mlc-Ai Xgrammar
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
xgrammar is an open-source library for efficient, flexible, and portable structured generation. A grammar optimizer introduced in 0.1.23 processes large grammars (>100k characters) at very low rates, and can be used for DOS of model providers. This issue is fixed in version 0.1.24.
Affected products
- Mlc-Ai Xgrammar: version 0.1.23 only
Published 2025-09-06. Last modified 2026-06-17.