CVE-2026-25048Disclosure(mlc-ai / xgrammar)

LOWCVSS 7.5 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch mlc-ai xgrammar systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

xgrammar is an open-source library for efficient, flexible, and portable structured generation. Prior to version 0.1.32, the multi-level nested syntax caused a segmentation fault (core dumped). This issue has been patched in version 0.1.32.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-674

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • xgrammar

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
xgrammar

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-05: 3Patch / Workaround · 2026-03-05: 1Technical Details · 2026-03-05: 303-05
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets4 URLs
Full discourse3 posts
  • CVE@CVEnew
    Patch

    CVE-2026-25048 xgrammar is an open-source library for efficient, flexible, and portable structured generation. Prior to version 0.1.32, the multi-level nested syntax caused a segmen… https://www.cve.org/CVERecord?id=CVE-2026-25048

    Post summary

    The statement highlights a segmentation fault issue in xgrammar before v0.1.32 that has been addressed in newer releases, indicating the availability of a patch.

    00000127
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-25048 Segmentation Fault in xgrammar Library Prior to Version 0.1.32 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25048 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    The tweet announces a segmentation fault vulnerability in the xgrammar library before version 0.1.32, directing readers to a Vulmon detail page for further information.

    0000031
    4.0K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-25048 - xgrammar: Multi-layer nesting causes DoS Intel Report: https://ift.tt/GYWJxAX

    Post summary

    An alert announces CVE‑2026‑25048, a denial‑of‑service flaw in xgrammar caused by multi‑layer nesting, and links to an Intel Report for additional information.

    0000032
    343 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmlc-aixgrammar---

Explore more