jline is vulnerable to Regular Expression Denial of Service (ReDoS)
75
High Risk
The built-in grep command in jline wraps an untrusted regular expression with .* on both sides, unless --line-regexp is set, and compiles that pattern with Java's backtracking regex engine. A short nested quantifier such as (a+)+b on a non-matching line makes the match consume CPU until the command thread stalls. A remote shell that exposes this command lets an unauthenticated user occupy a worker, and repeated sessions can exhaust the worker pool. The fix removes the .* wrapper, uses Matcher.find() for substring searches, and limits match time with SafeRegex.
You are affected if you are using a version that falls within the vulnerable range and your application exposes the built-in grep command to untrusted input.
jline is vulnerable to Regular Expression Denial of Service (ReDoS) in versions 3.0.0 - 3.30.14 and 4.0.0 - 4.3.0.
Upgrade the org.jline:jline library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.