Intel

AIKIDO-2026-898814

jline is vulnerable to Regular Expression Denial of Service (ReDoS)

Regular Expression Denial of Service (ReDoS)CVE-2026-77422 Published Yesterday

75

High Risk

This Affects:

JAVAjline
3.0.0 - 3.30.14
Fixed in 3.30.15
4.0.0 - 4.3.0
Fixed in 4.3.1
Are you affected? Scan for Free

TL;DR

The built-in grep command in jline wraps an untrusted regular expression with .* on both sides, unless --line-regexp is set, and compiles that pattern with Java's backtracking regex engine. A short nested quantifier such as (a+)+b on a non-matching line makes the match consume CPU until the command thread stalls. A remote shell that exposes this command lets an unauthenticated user occupy a worker, and repeated sessions can exhaust the worker pool. The fix removes the .* wrapper, uses Matcher.find() for substring searches, and limits match time with SafeRegex.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and your application exposes the built-in grep command to untrusted input.

Background info

jline is vulnerable to Regular Expression Denial of Service (ReDoS) in versions 3.0.0 - 3.30.14 and 4.0.0 - 4.3.0.

How to fix this

Upgrade the org.jline:jline library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform