Inefficient regular expression complexity in transformers - CVE-2025-1194
Published: May 12, 2025
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient input validation when processing untrusted input with a regular expressions. A remote attacker can pass specially crafted data to the application and perform regular expression denial of service (ReDos) attack.
Affected software
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
Maximo Application Suite Ai Service
watsonx Code Assistant On Prem
Maximo Application Suite - Monitor Component
App Connect Enterprise Certified Container
How to mitigate CVE-2025-1194
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.2.1
Maximo Application Suite Ai Service - update to 9.1.3
watsonx Code Assistant On Prem - update to 5.1.3
Maximo Application Suite - Monitor Component - update to 9.1.0
App Connect Enterprise Certified Container - addressed in versions 12.0.11, 12.11.0
External References
Related Security Bulletins
- Inefficient regular expression complexity in huggingface/transformers
- Multiple vulnerabilities in IBM App Connect Enterprise Certified Container
- IBM Maximo Application Suite - Monitor Component update for huggingface/transformers library
- IBM watsonx Code Assistant On Prem update for huggingface/transformers library
- IBM watsonx Orchestrate Cartridge for IBM Cloud Pak for Data update for transformers
- IBM Maximo AI Service update for huggingface/transformers