Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
CVE-LINKED INVENTORY12 SECURITY RECORDS

Hugging Face

Transformers

Affected and fixed version statements observed in the public BlackTree CVE catalogue. These statements describe vulnerability scope, not publisher support entitlement.

Lifecycle evidence status

Official registry publication history is available at transformers, but registry activity is not a publisher support boundary.

A missing support date does not mean the product is supported. CVE publication dates and affected-version ranges must not be interpreted as EOL dates.

CVE-observed version history

CVEPublishedAffected versionsFixed version informationPublisher evidence
CVE-2026-80047 1 Sep 2026 Transformers: 4.57.0 ≤ 5.16.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-14930 23 Dec 2025 4.57.1 For more information visit https://access.redhat.com/errata/RHSA-2026:30078 Update reference ↗
CVE-2025-14928 23 Dec 2025 4.57.0 For more information visit https://access.redhat.com/errata/RHSA-2026:30078 Update reference ↗
CVE-2025-14924 23 Dec 2025 95faabf0a6cd845f4c5548697e288a79e424b096 For Red Hat OpenShift AI 2.25.3 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this errata update: https://docs.redhat.com/en/documentation/red_hat_openshift_ai/ Update reference ↗
CVE-2025-14920 23 Dec 2025 9c8bd3fc1befe54f3efb9f385561eef49f060a70 For Red Hat OpenShift AI 2.25.3 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this errata update: https://docs.redhat.com/en/documentation/red_hat_openshift_ai/ Update reference ↗
CVE-2025-14926 23 Dec 2025 4.57.0 For more information visit https://access.redhat.com/errata/RHSA-2026:30078 Update reference ↗
CVE-2025-14927 23 Dec 2025 4.57.0 For more information visit https://access.redhat.com/errata/RHSA-2026:30078 Update reference ↗
CVE-2025-14921 23 Dec 2025 9c8bd3fc1befe54f3efb9f385561eef49f060a70 For Red Hat OpenShift AI 2.25.3 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this errata update: https://docs.redhat.com/en/documentation/red_hat_openshift_ai/ Update reference ↗
CVE-2025-14929 23 Dec 2025 d1c6310d6a02481d48d81607cba7840be04580d1 For Red Hat OpenShift AI 2.25.3 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this errata update: https://docs.redhat.com/en/documentation/red_hat_openshift_ai/ Update reference ↗
CVE-2024-11394 22 Nov 2024 026a173a64372e9602a16523b8fae9de4b0ff428 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2024-11393 22 Nov 2024 8820fe8b8c4b9da94cf1e4761876f85c562e0efe No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2024-11392 22 Nov 2024 940fde8dafaecb8f17b588c5078291f1c1a420c8 No fixed version is explicitly recorded in the structured CVE data. Use CVE record

How this record is maintained

The CVE inventory is reconciled automatically from cve.blacktree.nl. Exact identity matches link to existing Lifecycle product or package histories. Unmatched products stay in a prioritised publisher-source research queue, and Lifecycle marks the date gap instead of inferring a support boundary from vulnerability data.