PT-2026-97439 · Jline · Jline
CVE-2026-77422
·
Published
2026-06-30
·
Updated
2026-09-24
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
JLine versions 3.0.0 through 3.30.14
JLine versions prior to 4.3.1
Description
The built-in
grep command in the PosixCommands.java file accepts a user-controlled regular expression in the grep() function. Unless line-regexp mode is used, the software automatically adds a dot-star prefix and suffix before compiling the expression with Java's backtracking regular expression engine. This behavior expands the backtracking search space, allowing a short nested-quantifier expression evaluated against non-matching input to cause catastrophic backtracking. This results in excessive CPU consumption and can indefinitely block a command worker, leading to a denial-of-service, especially in remotely exposed shell sessions.Recommendations
Update JLine to version 3.30.15.
Update JLine to version 4.3.1.
As a temporary mitigation, avoid using the
grep() function with complex nested-quantifier regular expressions.Exploit
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jline