Missing Release of File Descriptor or Handle after Effective Lifetime in jline3 - #VU148448
Published: September 9, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to missing release of a file descriptor after its effective lifetime in the JLine3 Telnet server ConnectionManager.makeConnection() method when handling connections after the maximum connection limit is reached. A remote attacker can repeatedly open TCP connections while the server is at capacity to exhaust the per-process file descriptor limit.
Only applications that embed the remote-telnet module and expose its Telnet server are affected.