-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| transformers | pip | < 4.51.0 | 4.51.0 |
The vulnerability description explicitly points to the get_imports function in dynamic_module_utils.py as the source of the ReDoS vulnerability. The provided commit 126abe3461762e5fc180e7e614391d1b4ab051ca confirms this by showing the removal of the vulnerable regex-based implementation and its replacement with a safer AST-based approach. The patch evidence clearly shows the line with re.sub and the problematic regex that was removed, which is the root cause of the vulnerability. Therefore, I can confidently identify transformers.dynamic_module_utils.get_imports as the vulnerable function.
Ongoing coverage of React2Shell