CVE-2026-77421: Jline JLINE3

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

JLine is a Java library for handling console input. From 3.0.0 until 3.30.15 and 4.3.1, the JLine built-in nano editor's regex search mode passes a user-controlled search term from doSearch(String text) in builtins/src/main/java/org/jline/builtins/Nano.java to Java's backtracking regular expression engine without a timeout or backtracking bound. A nested-quantifier expression evaluated against non-matching buffer content can consume excessive CPU and indefinitely block the editor session thread, and remote multi-user deployments can lose a worker thread for each affected session. This issue is fixed in versions 3.30.15 and 4.3.1.

Affected products

  • Jline JLINE3: from 3.0.0, before 3.30.15 (fixed in 3.30.15); from 4.0.0, before 4.3.1 (fixed in 4.3.1)

Published 2026-09-23. Last modified 2026-09-30.