Dependency scanning
Check whether transformers is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CVE-2024-3568
Transformers Deserialization of Untrusted Data vulnerability
CVE-2025-3263
Transformers's ReDoS vulnerability in get_configuration_file can lead to catastrophic backtracking
CVE-2025-3262
Transformers vulnerable to ReDoS attack through its SETTING_RE variable
CVE-2025-3264
Transformers vulnerable to ReDoS attack through its get_imports() function
CVE-2025-6051
Hugging Face Transformers library has Regular Expression Denial of Service
CVE-2025-3777
Transformers's Improper Input Validation vulnerability can be exploited through username injection
CVE-2025-3263
Transformers's ReDoS vulnerability in get_configuration_file can lead to catastrophic backtracking
CVE-2025-3264
Transformers vulnerable to ReDoS attack through its get_imports() function
CVE-2025-1194
Transformers Regular Expression Denial of Service (ReDoS) vulnerability
CVE-2025-5197
Hugging Face Transformers Regular Expression Denial of Service (ReDoS) vulnerability
CVE-2024-12720
Transformers Regular Expression Denial of Service (ReDoS) vulnerability
CVE-2025-6638
Hugging Face Transformers is vulnerable to ReDoS through its MarianTokenizer
CVE-2025-3262
Transformers vulnerable to ReDoS attack through its SETTING_RE variable
CVE-2025-6921
Hugging Face Transformers vulnerable to Regular Expression Denial of Service (ReDoS) in the AdamWeightDecay optimizer
CVE-2025-3933
Transformers is vulnerable to ReDoS attack through its DonutProcessor class
CVE-2024-3568
Transformers Deserialization of Untrusted Data vulnerability
CVE-2026-4372
HuggingFace transformers vulnerable to remote code execution
CVE-2023-6730
CVE-2023-6730
CVE-2023-7018
CVE-2023-7018
CVE-2023-2800
CVE-2023-2800
CVE-2025-2099
CVE-2025-2099
CVE-2024-11392
CVE-2024-11392
CVE-2024-11394
CVE-2024-11394
CVE-2024-11393
CVE-2024-11393
CVE-2025-14930
CVE-2025-14930
CVE-2025-14928
CVE-2025-14928
CVE-2025-14926
CVE-2025-14926
CVE-2025-14927
CVE-2025-14927
CVE-2025-14920
CVE-2025-14920
CVE-2025-14921
CVE-2025-14921
CVE-2025-14924
CVE-2025-14924
CVE-2025-14929
CVE-2025-14929
CVE-2026-1839
HuggingFace Transformers allows for arbitrary code execution in the `Trainer` class
CVE-2024-11393
Deserialization of Untrusted Data in Hugging Face Transformers
CVE-2025-6051
Hugging Face Transformers library has Regular Expression Denial of Service
CVE-2025-1194
Transformers Regular Expression Denial of Service (ReDoS) vulnerability
CVE-2024-11394
Deserialization of Untrusted Data in Hugging Face Transformers
CVE-2024-12720
Transformers Regular Expression Denial of Service (ReDoS) vulnerability
CVE-2025-3933
Transformers is vulnerable to ReDoS attack through its DonutProcessor class
CVE-2025-5197
Hugging Face Transformers Regular Expression Denial of Service (ReDoS) vulnerability
CVE-2025-6638
Hugging Face Transformers is vulnerable to ReDoS through its MarianTokenizer
CVE-2025-3777
Transformers's Improper Input Validation vulnerability can be exploited through username injection
CVE-2024-11392
Deserialization of Untrusted Data in Hugging Face Transformers
CVE-2025-6921
Hugging Face Transformers vulnerable to Regular Expression Denial of Service (ReDoS) in the AdamWeightDecay optimizer
CVE-2025-2099
Hugging Face Transformers Regular Expression Denial of Service
CVE-2023-6730
transformers has a Deserialization of Untrusted Data vulnerability
CVE-2023-7018
transformers has a Deserialization of Untrusted Data vulnerability
CVE-2023-2800
transformers has Insecure Temporary File
Browse more PyPI advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes