Improper handling of exceptional conditions in jline3 - #VU148446
Published: September 9, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to improper handling of exceptional conditions in the JLine3 SSH server shell channel startup code when parsing client-supplied PTY dimensions. A remote user can open shell channels with absent or non-numeric COLUMNS or LINES values to cause a denial of service.
The exception prevents the channel cleanup callback from running, leaving the channel open and consuming session channel capacity.