SB2026090942 - Multiple vulnerabilities in jline3
Published: September 9, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 vulnerabilities.
1) Resource exhaustion (CVE-ID: CVE-2026-56740)
CWE-ID: CWE-400 - Resource exhaustion
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in the TelnetIO.readNEVariables() environment-variable accumulator when processing Telnet NEW-ENVIRON variable pairs. A remote attacker can send a large number of unique variable pairs to exhaust JVM heap memory.
The issue is reachable during Telnet NEW-ENVIRON negotiation before login.
2) Resource exhaustion (CVE-ID: CVE-2026-56741)
CWE-ID: CWE-400 - Resource exhaustion
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in the JLine3 remote-telnet module when processing Telnet NAWS terminal geometry subnegotiations. A remote attacker can repeatedly send alternating oversized terminal dimensions to trigger expensive rendering work and exhaust CPU resources.
The NAWS option is negotiated before any login sequence.
Remediation
Install update from vendor's website.