Resource exhaustion in jline3 - #VU148447
Published: September 9, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in the JLine3 remote-ssh shell channel handler when processing SSH window-change requests with unbounded terminal dimensions. A remote user can send alternating window-change requests with oversized terminal dimensions to cause a denial of service.
Exploitation requires valid SSH credentials and can consume session threads through CPU exhaustion.