7.5

CVE-2026-56740

Exploit

JLine: Unauthenticated Remote Memory Exhaustion via Unbounded Telnet NEW-ENVIRON Variables

JLine is a Java library for handling console input. Prior to 3.30.14, 4.0.16, and 4.2.1, the JLine3 Telnet server remote-telnet module does not limit the number of environment variables a client may inject via the Telnet NEW-ENVIRON option, and TelnetIO.readNEVariables() in TelnetIO.java:1127-1180 stores each variable pair in a HashMap held by ConnectionData, allowing an unauthenticated attacker to flood unique variable pairs before the terminating IAC SE byte and exhaust JVM heap memory with an OutOfMemoryError. This issue is fixed in versions 3.30.14, 4.0.16, and 4.2.1.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
JlineJline Version < 3.30.14
JlineJline Version >= 4.0.0 < 4.0.16
JlineJline Version >= 4.1.0 < 4.2.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.53% 0.423
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security-advisories@github.com 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-400 Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource.

https://github.com/jline/jline3/pull/2000
Issue Tracking
https://github.com/jline/jline3/releases/tag/4.0.16
Release Notes
https://github.com/jline/jline3/releases/tag/4.2.1
Release Notes
https://github.com/jline/jline3/security/advisories/GHSA-47qp-hqvx-6r3f
Vendor Advisory
Exploit
https://github.com/jline/jline3/pull/2001
Issue Tracking
https://github.com/jline/jline3/commit/0389f0ee6d0375901b602671ad5dafd4d1d4ee09
Patch
https://github.com/jline/jline3/commit/4ee3a73849ffb9a85ec748e4e8cd8f6d81f84f40
Patch
https://github.com/jline/jline3/commit/934f09e6128cee33c2b13d42b6e859c1ee2d194b
Patch
https://github.com/jline/jline3/releases/tag/jline-3.30.14
Release Notes