CVE-2025-3264 | huggingface transformers up to 4.50.x dynamic_module_utils.py get_imports redos (EUVD-2025-20214)
A vulnerability was found in huggingface transformers up to 4.50.x and classified as problematic. Affected by this issue is the function get_imports of the file dynamic_module_utils.py. The manipulation leads to inefficient regular expression complexity.
This vulnerability is handled as CVE-2025-3264. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.