Security Advisory

CVE-2025-48058

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-06-20 00:39:06
Last updated 2025-06-20 13:28:27
Assigner GitHub_M
State PUBLISHED

Description

PowSyBl (Power System Blocks) is a framework to build power system oriented software. Prior to version 6.7.2, there is a potential polynomial Regular Expression Denial of Service (ReDoS) vulnerability in the PowSyBls DataSource mechanism. If successfully exploited, a malicious actor can cause significant CPU consumption due to regex backtracking — even with polynomial patterns. This issue has been patched in com.powsybl:powsybl-commons: 6.7.2.