PT-2026-97439 · Jline · Jline

CVE-2026-77422

·

Published

2026-06-30

·

Updated

2026-09-24

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions JLine versions 3.0.0 through 3.30.14 JLine versions prior to 4.3.1
Description The built-in grep command in the PosixCommands.java file accepts a user-controlled regular expression in the grep() function. Unless line-regexp mode is used, the software automatically adds a dot-star prefix and suffix before compiling the expression with Java's backtracking regular expression engine. This behavior expands the backtracking search space, allowing a short nested-quantifier expression evaluated against non-matching input to cause catastrophic backtracking. This results in excessive CPU consumption and can indefinitely block a command worker, leading to a denial-of-service, especially in remotely exposed shell sessions.
Recommendations Update JLine to version 3.30.15. Update JLine to version 4.3.1. As a temporary mitigation, avoid using the grep() function with complex nested-quantifier regular expressions.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-15230
CVE-2026-77422
GHSA-R2XF-8XR9-62GW

Affected Products

Jline