CVE-2025-58446: Mlc-Ai Xgrammar

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

xgrammar is an open-source library for efficient, flexible, and portable structured generation. A grammar optimizer introduced in 0.1.23 processes large grammars (>100k characters) at very low rates, and can be used for DOS of model providers. This issue is fixed in version 0.1.24.

Affected products

  • Mlc-Ai Xgrammar: version 0.1.23 only

Published 2025-09-06. Last modified 2026-06-17.