CVE-2026-77423: JLine: ReDoS in Built-in Less Viewer Search

Published Sep 23, 2026
·
Updated

JLine is a Java library for handling console input. From 3.0.0 until 3.30.15 and 4.3.1, the JLine built-in less viewer passes user-controlled search and display-filter patterns from getPattern(boolean doDisplayPattern) in builtins/src/main/java/org/jline/builtins/Less.java directly to Java's backtracking regular expression engine and repeatedly applies them to file content. A nested-quantifier expression evaluated against non-matching lines can consume excessive CPU and indefinitely block the session thread, and repeated sessions in Telnet or SSH deployments can exhaust a bounded worker pool. This issue is fixed in versions 3.30.15 and 4.3.1.

Affected Software

1 affected component
jline jline>=3.0.0<3.30.15, >=4.0.0<4.3.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade JLine to a version that resolves this vulnerability.

    Fixed in 3.30.15
  2. Upgrade

    Upgrade JLine to a version that resolves this vulnerability.

    Fixed in 4.3.1

Event History

Sep 23, 2026
CVE Published
via MITRE·06:17 PM
Data Sourced
via MITRE·06:17 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:19 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are most exposed to service disruption?

Deployments that expose JLine's built-in less viewer through Telnet or SSH are particularly exposed. Repeated malicious sessions can consume the bounded worker pool after each session blocks its thread.

2

What must an attacker be able to do to trigger the issue?

An attacker needs to supply a search or display-filter pattern to the built-in less viewer. A nested-quantifier regular expression evaluated against non-matching file lines can consume excessive CPU and indefinitely block the session thread.

3

Are standard JLine versions affected?

The affected range is JLine versions from 3.0.0 up to 3.30.15, as well as version 4.3.1. The issue is fixed in versions 3.30.15 and 4.3.1.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203