PT-2026-97438 · Jline · Jline

CVE-2026-77421

·

Published

2026-09-23

·

Updated

2026-09-23

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions JLine versions 3.0.0 through 3.30.14 JLine versions 4.x through 4.3.0
Description The built-in nano editor in JLine handles regex search mode by passing a user-controlled search term from the doSearch(String text) function in builtins/src/main/java/org/jline/builtins/Nano.java to Java's backtracking regular expression engine without a timeout or backtracking bound. A crafted nested-quantifier expression evaluated against non-matching buffer content can cause catastrophic backtracking, leading to excessive CPU consumption and indefinitely blocking the editor session thread. In remote multi-user deployments, this can result in a denial of service as worker threads are occupied for each affected session.
Recommendations Update JLine to version 3.30.15. Update JLine to version 4.3.1.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77421
GHSA-PH9C-7HW9-VHHW

Affected Products

Jline