HIGHMaven →
JLine3 Telnet server: Unauthenticated Remote Memory Exhaustion via Unbounded Telnet NEW-ENVIRON Variables
JLine3 Telnet server: Unauthenticated Remote Memory Exhaustion via Unbounded Telnet NEW-ENVIRON Variables
Affected packages
- org.jline:jline-remote-telnet— before 4.2.1
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- —
- EPSS percentile
- —
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.
Sources
- https://github.com/jline/jline3/security/advisories/GHSA-47qp-hqvx-6r3f
- https://nvd.nist.gov/vuln/detail/CVE-2026-56740
- https://github.com/jline/jline3/pull/2000
- https://github.com/jline/jline3/pull/2001
- https://github.com/jline/jline3/commit/0389f0ee6d0375901b602671ad5dafd4d1d4ee09
- https://github.com/jline/jline3/commit/4ee3a73849ffb9a85ec748e4e8cd8f6d81f84f40
- https://github.com/jline/jline3/commit/934f09e6128cee33c2b13d42b6e859c1ee2d194b
- https://github.com/jline/jline3
- https://github.com/jline/jline3/releases/tag/4.0.16
- https://github.com/jline/jline3/releases/tag/4.2.1
- https://github.com/jline/jline3/releases/tag/jline-3.30.14
Structured record: https://osv.dev/vulnerability/GHSA-47qp-hqvx-6r3f
Recommended response stack
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta