Improper handling of exceptional conditions in jline3 - #VU148446

 

Improper handling of exceptional conditions in jline3 - #VU148446

Published: September 9, 2026


Vulnerability identifier: #VU148446
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-755
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to improper handling of exceptional conditions in the JLine3 SSH server shell channel startup code when parsing client-supplied PTY dimensions. A remote user can open shell channels with absent or non-numeric COLUMNS or LINES values to cause a denial of service.

The exception prevents the channel cleanup callback from running, leaving the channel open and consuming session channel capacity.


Affected software

jline3

Remediation

Install security update from vendor's website.

jline3 - update to 4.4.3

External References

Related Security Bulletins