PT-2026-97438 · Jline · Jline
CVE-2026-77421
·
Published
2026-09-23
·
Updated
2026-09-23
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
JLine versions 3.0.0 through 3.30.14
JLine versions 4.x through 4.3.0
Description
The built-in nano editor in JLine handles regex search mode by passing a user-controlled search term from the
doSearch(String text) function in builtins/src/main/java/org/jline/builtins/Nano.java to Java's backtracking regular expression engine without a timeout or backtracking bound. A crafted nested-quantifier expression evaluated against non-matching buffer content can cause catastrophic backtracking, leading to excessive CPU consumption and indefinitely blocking the editor session thread. In remote multi-user deployments, this can result in a denial of service as worker threads are occupied for each affected session.Recommendations
Update JLine to version 3.30.15.
Update JLine to version 4.3.1.
Exploit
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jline