Resource exhaustion in jline3 - CVE-2026-56741

 

Resource exhaustion in jline3 - CVE-2026-56741

Published: September 9, 2026


Vulnerability identifier: #VU148444
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-56741
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to uncontrolled resource consumption in the JLine3 remote-telnet module when processing Telnet NAWS terminal geometry subnegotiations. A remote attacker can repeatedly send alternating oversized terminal dimensions to trigger expensive rendering work and exhaust CPU resources.

The NAWS option is negotiated before any login sequence.


Affected software

jline3

How to mitigate CVE-2026-56741

Install security update from vendor's website.

jline3 - addressed in versions 3.30.14, 4.2.1

External References

Related Security Bulletins