PT-2026-97437 · Jline · Jline
CVE-2026-77420
·
Published
2026-09-23
·
Updated
2026-09-29
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
JLine versions 3.0.0 through 3.30.14
JLine versions 4.x through 4.3.0
Description
JLine is a Java library for handling console input. The
matchPatterns(String patterns, String line) function in DefaultHistory.java converts the HISTORY IGNORE configuration value into a Java regular expression but only escapes part of its syntax. This allows regex metacharacters such as (, ), +, ?, {, }, [, and ] to reach the backtracking engine. An attacker who can control application or user configuration can provide a nested-quantifier expression, such as (a+)+b, which causes catastrophic backtracking—a state where the regex engine takes an exponential amount of time to determine that a string does not match a pattern. This results in excessive CPU consumption and indefinitely blocks the reader thread, leading to a denial-of-service.Recommendations
Update JLine to version 3.30.15.
Update JLine to version 4.3.1.
Exploit
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jline