Uncontrolled Recursion in XGrammar - CVE-2026-25048
Published: April 24, 2026
XGrammar
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled recursion in the grammar compiler when parsing a malicious grammar rule with deeply nested parentheses. A remote attacker can supply a specially crafted grammar input to cause a denial of service.
The issue can result in a segmentation fault, stack overflow, or memory exhaustion.