Transformers
This hub aggregates every CVE we track for Transformers, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
30
CVEs tracked
2
Critical
20
High
0
In CISA KEV
Severity distribution
HIGH20MEDIUM7CRITICAL2LOW1
Monthly trend
0
0
0
0
3
0
0
0
1
1
1
0
5
1
3
0
0
8
0
0
0
1
1
1
2024-072026-06
Latest CVEs
The 15 most recently published vulnerabilities affecting Transformers.
- CVE-2026-5241Policy Bypass in LightGlue Nested Config Resolution in huggingface/transformers9.6
- CVE-2026-4372Arbitrary Remote Code Execution via `_attn_implementation_internal` Config Injection in huggingface/transformers7.8
- CVE-2026-1839Arbitrary Code Execution via Unsafe torch.load() in Trainer Checkpoint Loading in huggingface/transformers7.8
- CVE-2025-14930Hugging Face Transformers GLM4 Deserialization of Untrusted Data Remote Code Execution Vulnerability7.8
- CVE-2025-14928Hugging Face Transformers HuBERT convert_config Code Injection Remote Code Execution Vulnerability7.8
- CVE-2025-14924Hugging Face Transformers megatron_gpt2 Deserialization of Untrusted Data Remote Code Execution Vulnerability7.8
- CVE-2025-14920Hugging Face Transformers Perceiver Model Deserialization of Untrusted Data Remote Code Execution Vulnerability7.8
- CVE-2025-14926Hugging Face Transformers SEW convert_config Code Injection Remote Code Execution Vulnerability7.8
- CVE-2025-14927Hugging Face Transformers SEW-D convert_config Code Injection Remote Code Execution Vulnerability7.8
- CVE-2025-14921Hugging Face Transformers Transformer-XL Model Deserialization of Untrusted Data Remote Code Execution Vulnerability7.8
- CVE-2025-14929Hugging Face Transformers X-CLIP Checkpoint Conversion Deserialization of Untrusted Data Remote Code Execution Vulnerability7.8
- CVE-2025-6921Regular Expression Denial of Service (ReDoS) in huggingface/transformers7.5
- CVE-2025-6051Regular Expression Denial of Service (ReDoS) in huggingface/transformers5.3
- CVE-2025-6638Regular Expression Denial of Service (ReDoS) in huggingface/transformers7.5
- CVE-2025-5197Regular Expression Denial of Service (ReDoS) in huggingface/transformers5.3
Product normalization is registry-driven with AI assist and human review. How it works