{"id":"CVE-2025-48059","summary":"PowSyBl Core Contains a Polynomial ReDoS in RegexCriterion","details":"PowSyBl (Power System Blocks) is a framework to build power system oriented software. In com.powsybl:powsybl-iidm-criteria versions 6.3.0 to before 6.7.2 and com.powsybl:powsybl-contingency-api versions 5.0.0 to before 6.3.0, there is a a potential polynomial Regular Expression Denial of Service (ReDoS) vulnerability in the RegexCriterion class. This class compiles and evaluates an unvalidated, user-supplied regular expression against the identifier of an Identifiable object via Pattern.compile(regex).matcher(id).find(). If successfully exploited, a malicious actor can cause significant CPU exhaustion through repeated or recursive filter(...) calls — especially if performed over large network models or filtering operations. This issue has been patched in com.powsybl:powsybl-iidm-criteria 6.7.2.","aliases":["GHSA-8qjw-9xgm-c9ff"],"modified":"2026-08-12T03:51:20.894429133Z","published":"2025-06-20T16:50:35.974Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/48xxx/CVE-2025-48059.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-1333"]},"references":[{"type":"WEB","url":"https://github.com/powsybl/powsybl-core/releases/tag/v6.7.2"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/48xxx/CVE-2025-48059.json"},{"type":"ADVISORY","url":"https://github.com/powsybl/powsybl-core/security/advisories/GHSA-8qjw-9xgm-c9ff"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-48059"},{"type":"FIX","url":"https://github.com/powsybl/powsybl-core/commit/d8398f689a5ccd505bd62eee2bd6670a29133110"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/powsybl/powsybl-core","events":[{"introduced":"a2f1f99612dcece3d50f8f8c4a488e5951363e0a"},{"fixed":"4fa8b7d8b7138489b8904bfa4620eae0d74378e7"},{"introduced":"d456d23cd8e49fc5b0ee44ef58fce171b7527ef5"},{"fixed":"a2f1f99612dcece3d50f8f8c4a488e5951363e0a"}],"database_specific":{"extracted_events":[{"introduced":"6.3.0"},{"fixed":"6.7.2"},{"introduced":"5.0.0"},{"fixed":"6.3.0"}],"source":"AFFECTED_FIELD"}}],"versions":["v6.7.1","v6.7.0","v6.7.0-RC1","v6.6.0-RC1","v6.5.0-RC1","v6.4.0-RC1","v6.3.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-48059.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U"}]}