Resource exhaustion in jline3 - CVE-2026-56740
Published: September 9, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in the TelnetIO.readNEVariables() environment-variable accumulator when processing Telnet NEW-ENVIRON variable pairs. A remote attacker can send a large number of unique variable pairs to exhaust JVM heap memory.
The issue is reachable during Telnet NEW-ENVIRON negotiation before login.