CVE-2025-48059

LOW

Com.powsybl Powsybl-iidm-criteria < 6.7.2 - Denial of Service

Title source: rule
STIX 2.1

Description

PowSyBl (Power System Blocks) is a framework to build power system oriented software. In com.powsybl:powsybl-iidm-criteria versions 6.3.0 to before 6.7.2 and com.powsybl:powsybl-contingency-api versions 5.0.0 to before 6.3.0, there is a a potential polynomial Regular Expression Denial of Service (ReDoS) vulnerability in the RegexCriterion class. This class compiles and evaluates an unvalidated, user-supplied regular expression against the identifier of an Identifiable object via Pattern.compile(regex).matcher(id).find(). If successfully exploited, a malicious actor can cause significant CPU exhaustion through repeated or recursive filter(...) calls — especially if performed over large network models or filtering operations. This issue has been patched in com.powsybl:powsybl-iidm-criteria 6.7.2.

Scores

CVSS v4 2.7
EPSS 0.0042
EPSS Percentile 61.7%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-1333
Status published
Products (4)
com.powsybl/powsybl-contingency-api 5.0.0 - 6.3.0Maven
com.powsybl/powsybl-iidm-criteria 6.3.0 - 6.7.2Maven
powsybl/powsybl-core >= 5.0.0, < 6.3.0
powsybl/powsybl-core >= 6.3.0, < 6.7.2
Published Jun 20, 2025
Tracked Since Feb 18, 2026