PT-2026-97437 · Jline · Jline

CVE-2026-77420

·

Published

2026-09-23

·

Updated

2026-09-29

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions JLine versions 3.0.0 through 3.30.14 JLine versions 4.x through 4.3.0
Description JLine is a Java library for handling console input. The matchPatterns(String patterns, String line) function in DefaultHistory.java converts the HISTORY IGNORE configuration value into a Java regular expression but only escapes part of its syntax. This allows regex metacharacters such as (, ), +, ?, {, }, [, and ] to reach the backtracking engine. An attacker who can control application or user configuration can provide a nested-quantifier expression, such as (a+)+b, which causes catastrophic backtracking—a state where the regex engine takes an exponential amount of time to determine that a string does not match a pattern. This results in excessive CPU consumption and indefinitely blocks the reader thread, leading to a denial-of-service.
Recommendations Update JLine to version 3.30.15. Update JLine to version 4.3.1.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77420
GHSA-5Q95-HRPC-M3W3

Affected Products

Jline