7.5

CVE-2026-56741

Exploit

JLine: Unauthenticated Remote DoS via Unbounded Telnet NAWS Terminal Geometry

JLine is a Java library for handling console input. Prior to 3.30.14, 4.0.16, and 4.2.1, the JLine3 Telnet server remote-telnet module does not apply an upper bound to terminal dimensions received via the Telnet NAWS option, and TelnetIO.handleNAWS() in TelnetIO.java:856-879 reads client-supplied width and height as 16-bit unsigned integers and passes values such as 65535x65535 to setTerminalGeometry(), allowing an unauthenticated remote attacker to repeatedly alternate values and trigger continuous expensive rendering work that causes CPU exhaustion and denial of service. This issue is fixed in versions 3.30.14, 4.0.16, and 4.2.1.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
JlineJline Version < 3.30.14
JlineJline Version >= 4.0.0 < 4.0.16
JlineJline Version >= 4.1.0 < 4.2.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.53% 0.424
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security-advisories@github.com 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-400 Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource.

https://github.com/jline/jline3/security/advisories/GHSA-2r2c-cx56-8933
Vendor Advisory
Exploit
https://github.com/jline/jline3/pull/2000
Issue Tracking
https://github.com/jline/jline3/commit/3ea9cad8699714dc072fade29d36be0d1e23d708
Patch
https://github.com/jline/jline3/commit/733eb353dca7b0ea0252e724445b6defa29c393e
Patch
https://github.com/jline/jline3/commit/86b7ba7801988aadb1a67555629522a71d603bd3
Patch
https://github.com/jline/jline3/releases/tag/4.0.16
Release Notes
https://github.com/jline/jline3/releases/tag/4.2.1
Release Notes