PatchSiren cyber security CVE debrief
CVE-2026-77420 jline CVE debrief
CVE-2026-77420 is a vulnerability in the JLine Java library for handling console input, allowing attackers to supply nested-quantifier expressions that can cause excessive CPU consumption and indefinitely block the reader thread. This issue affects versions 3.0.0 to 3.30.14 and 4.3.0 of the library. Defenders should assess exposure, particularly in Java applications with user-configurable inputs, and prioritize upgrading to fixed versions 3.30.15 or 4.3.1. The vulnerability can lead to potential CPU consumption and reader thread blocking, emphasizing the need for verification of affected versions and configurations.
- Vendor
- jline
- Product
- jline3
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-23
- Original CVE updated
- 2026-09-29
- Advisory published
- 2026-09-23
- Advisory updated
- 2026-09-29
Who should care
Defenders responsible for Java applications using the JLine library, particularly those with user-configurable inputs, should assess exposure and prioritize upgrading to fixed versions.
Why it matters
CVE-2026-77420 allows attackers to cause CPU consumption and reader thread blocking via nested-quantifier expressions in JLine library versions 3.0.0 to 3.30.14 and 4.3.0. Defenders should verify exposure, prioritize upgrading to fixed versions, and monitor for excessive CPU consumption.
- Potential for excessive CPU consumption by the reader thread
- Possible indefinite blocking of the reader thread
- Need for verification of affected versions and configuration
- Priority for upgrading to versions 3.30.15 or 4.3.1
Technical summary
The DefaultHistory.matchPatterns function in JLine library versions 3.0.0 to 3.30.14 and 4.3.0 converts the HISTORY_IGNORE configuration value into a Java regular expression, allowing for nested-quantifier expressions. These expressions can be supplied by an attacker who controls application or user configuration, leading to excessive CPU consumption and indefinite blocking of the reader thread. The vulnerability is fixed in versions 3.30.15 and 4.3.1. Defenders should prioritize verifying and upgrading to these versions to prevent potential CPU consumption and reader thread blocking.
Defensive priority
Defenders should prioritize verifying and upgrading to versions 3.30.15 or 4.3.1 of the JLine library to prevent potential CPU consumption and reader thread blocking.
Recommended defensive actions
- Verify and upgrade to versions 3.30.15 or 4.3.1 of the JLine library
- Review application or user configuration for potential vulnerabilities
- Monitor for excessive CPU consumption and reader thread blocking
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, including its description, CVSS score, and affected versions. However, the corpus does not establish versions, exploitation, impact, or remediation beyond fixing the versions to 3.30.15 or 4.3.1.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-77420 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-77420
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-77420 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-77420
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/jline/jline3/commit/1d5fc3099e77938b971e197211cad2d4fbb17541
-
Source reference
Unverified legacy reference
URL: https://github.com/jline/jline3/commit/341ee69ccc57b7733c1b40d6993219b64b3206ae
-
Source reference
Unverified legacy reference
URL: https://github.com/jline/jline3/pull/2012
-
Source reference
Unverified legacy reference
URL: https://github.com/jline/jline3/pull/2018
-
Source reference
Unverified legacy reference
URL: https://github.com/jline/jline3/releases/tag/4.3.1
-
Source reference
Unverified legacy reference
URL: https://github.com/jline/jline3/releases/tag/jline-3.30.15
-
Source reference
Unverified legacy reference
URL: https://github.com/jline/jline3/security/advisories/GHSA-5q95-hrpc-m3w3
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.