Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-56740

Опубликовано: 17 июл. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

JLine is a Java library for handling console input. Prior to 3.30.14, 4.0.16, and 4.2.1, the JLine3 Telnet server remote-telnet module does not limit the number of environment variables a client may inject via the Telnet NEW-ENVIRON option, and TelnetIO.readNEVariables() in TelnetIO.java:1127-1180 stores each variable pair in a HashMap held by ConnectionData, allowing an unauthenticated attacker to flood unique variable pairs before the terminating IAC SE byte and exhaust JVM heap memory with an OutOfMemoryError. This issue is fixed in versions 3.30.14, 4.0.16, and 4.2.1.

A flaw was found in the JLine3 Telnet server remote-telnet module. An unauthenticated remote attacker can exploit this vulnerability by injecting an excessive number of environment variables through the Telnet NEW-ENVIRON option. This action causes the server to store numerous variable pairs, leading to the exhaustion of Java Virtual Machine (JVM) heap memory and a Denial of Service (DoS) condition.

Отчет

This is a denial of service vulnerability in the JLine3 Telnet server module. An unauthenticated remote attacker can exploit this flaw by injecting excessive environment variables, leading to JVM heap memory exhaustion and a denial of service in applications that expose this vulnerable Telnet server functionality.

Меры по смягчению последствий

To mitigate this issue, restrict network access to applications that expose the JLine3 Telnet server module. If the Telnet server functionality is not required, consider disabling the JLine3 remote-telnet module within the affected application's configuration. Consult application-specific documentation for instructions on disabling or configuring the Telnet server. A restart of the affected application or service may be required for changes to take effect.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Fuse 7jline-remote-telnetNot affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-spark-operator-rhel9Affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-th06-cpu-torch210-py312-rhel9Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-th06-cpu-torch291-py312-rhel9Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-th06-cuda130-torch210-py312-rhel9Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-th06-cuda130-torch291-py312-rhel9Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-th06-rocm64-torch291-py312-rhel9Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-th-torch-cpu-py312-rhel9Affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-th-torch-cuda-py312-rhel9Affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2501965org.jline/jline-remote-telnet: JLine3 Telnet Server: Denial of Service via excessive environment variable injection

EPSS

Процентиль: 47%
0.00592
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
2 месяца назад

JLine is a Java library for handling console input. Prior to 3.30.14, 4.0.16, and 4.2.1, the JLine3 Telnet server remote-telnet module does not limit the number of environment variables a client may inject via the Telnet NEW-ENVIRON option, and TelnetIO.readNEVariables() in TelnetIO.java:1127-1180 stores each variable pair in a HashMap held by ConnectionData, allowing an unauthenticated attacker to flood unique variable pairs before the terminating IAC SE byte and exhaust JVM heap memory with an OutOfMemoryError. This issue is fixed in versions 3.30.14, 4.0.16, and 4.2.1.

CVSS3: 7.5
nvd
2 месяца назад

JLine is a Java library for handling console input. Prior to 3.30.14, 4.0.16, and 4.2.1, the JLine3 Telnet server remote-telnet module does not limit the number of environment variables a client may inject via the Telnet NEW-ENVIRON option, and TelnetIO.readNEVariables() in TelnetIO.java:1127-1180 stores each variable pair in a HashMap held by ConnectionData, allowing an unauthenticated attacker to flood unique variable pairs before the terminating IAC SE byte and exhaust JVM heap memory with an OutOfMemoryError. This issue is fixed in versions 3.30.14, 4.0.16, and 4.2.1.

CVSS3: 7.5
debian
2 месяца назад

JLine is a Java library for handling console input. Prior to 3.30.14, ...

CVSS3: 7.5
github
3 месяца назад

JLine3 Telnet server: Unauthenticated Remote Memory Exhaustion via Unbounded Telnet NEW-ENVIRON Variables

suse-cvrf
2 месяца назад

Security update for jline3

EPSS

Процентиль: 47%
0.00592
Низкий

7.5 High

CVSS3