OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-77423

HIGH · CVSS 7.5 EPSS 0.39% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-23 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

The JLine library in Java versions 3.0.0 to 3.30.15 and 4.3.1 is vulnerable to a denial-of-service attack due to improper handling of user-controlled regular expression patterns, which can lead to excessive CPU consumption and thread blocking. This vulnerability poses a significant risk, particularly for applications using Telnet or SSH, as it can exhaust worker pools and disrupt service availability. Organizations utilizing affected JLine versions should prioritize updating to the patched versions 3.30.15 or 4.3.1 to mitigate this high-severity risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-77423
Severity
HIGH
CVSS
7.5
EPSS
0.39%
Java

Original NVD Description

JLine is a Java library for handling console input. From 3.0.0 until 3.30.15 and 4.3.1, the JLine built-in less viewer passes user-controlled search and display-filter patterns from getPattern(boolean doDisplayPattern) in builtins/src/main/java/org/jline/builtins/Less.java directly to Java's backtracking regular expression engine and repeatedly applies them to file content. A nested-quantifier expression evaluated against non-matching lines can consume excessive CPU and indefinitely block the session thread, and repeated sessions in Telnet or SSH deployments can exhaust a bounded worker pool. This issue is fixed in versions 3.30.15 and 4.3.1.