PT-2025-26255 · Powsybl · Powsybl

·

CVE-2025-48058

·

Published

2025-06-19

·

Updated

2025-06-21

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions PowSyBl versions prior to 6.7.2
Description The issue is a potential polynomial Regular Expression Denial of Service (ReDoS) vulnerability in the PowSyBl's DataSource mechanism. This vulnerability can be exploited when the listNames(String regex) method is called on a DataSource with a user-supplied regular expression, allowing a malicious actor to cause significant CPU consumption due to regex backtracking. The attack requires control over the regex input and influence over the file/resource names being matched. In a multi-tenant environment, this can degrade the performance and availability of the server, affecting other users of the application.
Recommendations For versions prior to 6.7.2, update to com.powsybl:powsybl-commons:6.7.2 or higher to patch the vulnerability. As a temporary workaround, consider restricting access to the listNames(String regex) method or validating user-supplied regular expressions to minimize the risk of exploitation. Avoid using unvalidated user-supplied regular expressions in the listNames(String regex) method until the issue is resolved.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-48058
GHSA-RQPX-F6RC-7HM5

Affected Products

Powsybl