xgrammar
PyPI4 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting xgrammarpage 1 of 1
- CVE-2025-32381MEDIUMCVSS 6.5EG 6.5✓ Fixed in 0.1.182025-04-09
vulnerable: 0.1.0 ... 0.1.9 (20 versions)
XGrammar is an open-source library for efficient, flexible, and portable structured generation. Prior to 0.1.18, Xgrammar includes a cache for compiled grammars to increase performance with repeated use of the same grammar. This cache is h…
- CVE-2025-57809HIGHCVSS 7.5EG 7.5✓ Fixed in 0.1.212025-08-25
vulnerable: 0.1.0 ... 0.1.9 (23 versions)
XGrammar is an open-source library for efficient, flexible, and portable structured generation. Prior to version 0.1.21, XGrammar has an infinite recursion issue in the grammar. This issue has been resolved in version 0.1.21.
- CVE-2025-58446HIGHCVSS 7.5EG 7.5✓ Fixed in 0.1.242025-09-06
vulnerable: 0.1.23
xgrammar is an open-source library for efficient, flexible, and portable structured generation. A grammar optimizer introduced in 0.1.23 processes large grammars (>100k characters) at very low rates, and can be used for DOS of model provid…
- CVE-2026-25048HIGHCVSS 7.5EG 7.5✓ Fixed in 0.1.322026-03-05
vulnerable: 0.1.0 ... 0.1.9 (34 versions)
xgrammar is an open-source library for efficient, flexible, and portable structured generation. Prior to version 0.1.32, the multi-level nested syntax caused a segmentation fault (core dumped). This issue has been patched in version 0.1.32.
Check whether xgrammar is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for xgrammar CVEs against the assets you own.
Start Free Scan →