ReDoS Vulnerability in PowSyBl DataSource Mechanism
CVE-2025-48058

6.3MEDIUM

Key Information:

Vendor

Powsybl

Vendor
CVE Published:
20 June 2025

What is CVE-2025-48058?

The PowSyBl framework, designed for building power system oriented software, contains a significant vulnerability within its DataSource mechanism. Before version 6.7.2, a potential polynomial Regular Expression Denial of Service (ReDoS) vulnerability exists, wherein an attacker can exploit the behavior of regex backtracking to induce excessive CPU usage. This could severely degrade system performance or lead to service outages. The issue has been resolved in version 6.7.2, emphasizing the importance of updating to this patched version to maintain system integrity.

Affected Version(s)

powsybl-core < 6.7.2

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-48058 : ReDoS Vulnerability in PowSyBl DataSource Mechanism