Dismissed
(no matching packages found)
Permalink
CVE-2026-56740
7.5 HIGH
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): None (N)
- User Interaction (UI): None (N)
- Scope (S): Unchanged (U)
- Confidentiality (C): None (N)
- Integrity (I): None (N)
- Availability (A): High (H)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): None (N)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): None (N)
- Modified Availability (MA): High (H)
Activity log
- Created & dismissed (no matching packages found) suggestion
JLine: Unauthenticated Remote Memory Exhaustion via Unbounded Telnet NEW-ENVIRON Variables
JLine is a Java library for handling console input. Prior to 3.30.14, 4.0.16, and 4.2.1, the JLine3 Telnet server remote-telnet module does not limit the number of environment variables a client may inject via the Telnet NEW-ENVIRON option, and TelnetIO.readNEVariables() in TelnetIO.java:1127-1180 stores each variable pair in a HashMap held by ConnectionData, allowing an unauthenticated attacker to flood unique variable pairs before the terminating IAC SE byte and exhaust JVM heap memory with an OutOfMemoryError. This issue is fixed in versions 3.30.14, 4.0.16, and 4.2.1.
References
-
https://github.com/jline/jline3/security/advisories/GHSA-47qp-hqvx-6r3f x_refsource_CONFIRM
-
https://github.com/jline/jline3/pull/2000 x_refsource_MISC
-
https://github.com/jline/jline3/pull/2001 x_refsource_MISC
-
https://github.com/jline/jline3/releases/tag/4.0.16 x_refsource_MISC
-
https://github.com/jline/jline3/releases/tag/4.2.1 x_refsource_MISC
-
https://github.com/jline/jline3/releases/tag/jline-3.30.14 x_refsource_MISC
Affected products
jline3
- ==>= 4.1.0, < 4.2.1
- ==< 3.30.14
- ==>= 4.0.0, < 4.0.16