jline has 6 CVEs on record. Disclosure cadence is accelerating: 4 in the last 90 days against 2 in the 90 before. The busiest recent month was September 2026 with 4. The median CVSS is 7.5 (high). None have a confirmed exploitation report. The most common weakness class is CWE-1333 (4). Most affected products: jline3 (4), org.jline:jline-remote-telnet (2).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.5
- Publish → KEV
- —
- Last 90 days
- 4 prev 2
Weakness classes
Products
- jline3 4
- org.jline:jline-remote-telnet 2
Worst active — by depth score
CVE-2026-77423High· 7.5JLine is a Java library for handling console input41CVE-2026-77422High· 7.5JLine is a Java library for handling console input41GHSA-47qp-hqvx-6r3fHigh· 7.5JLine3 Telnet server: Unauthenticated Remote Memory Exhaustion via Unbounded Telnet NEW-ENVIRON Variables41GHSA-2r2c-cx56-8933High· 7.5JLine3 Telnet server: Unauthenticated Remote DoS via Unbounded Telnet NAWS Terminal Geometry41CVE-2026-77421Medium· 6.5JLine is a Java library for handling console input36
jline vulnerabilities
CVEs affecting jline, newest first. Open any entry for full detail, references, and exploit status.
6 CVEsRSS
CVE-2026-77423High· 7.5JLine is a Java library for handling console input
JLine is a Java library for handling console input. From 3.0.0 until 3.30.15 and 4.3.1, the JLine built-in less viewer passes user-controlled search and display-filter patterns from getPattern(boolean doDisplayPattern) in builtins/src/ma…
CVE-2026-77420Medium· 5.5JLine is a Java library for handling console input
JLine is a Java library for handling console input. From 3.0.0 until 3.30.15 and 4.3.1, DefaultHistory.matchPatterns(String patterns, String line) in reader/src/main/java/org/jline/reader/impl/history/DefaultHistory.java converts the HIS…
CVE-2026-77422High· 7.5JLine is a Java library for handling console input
JLine is a Java library for handling console input. From 3.0.0 until 3.30.15 and 4.3.1, the JLine built-in grep command in builtins/src/main/java/org/jline/builtins/PosixCommands.java accepts a user-controlled regular expression in grep(…
CVE-2026-77421Medium· 6.5JLine is a Java library for handling console input
JLine is a Java library for handling console input. From 3.0.0 until 3.30.15 and 4.3.1, the JLine built-in nano editor's regex search mode passes a user-controlled search term from doSearch(String text) in builtins/src/main/java/org/jlin…
GHSA-2r2c-cx56-8933High· 7.5JLine3 Telnet server: Unauthenticated Remote DoS via Unbounded Telnet NAWS Terminal Geometry
JLine3 Telnet server: Unauthenticated Remote DoS via Unbounded Telnet NAWS Terminal Geometry
GHSA-47qp-hqvx-6r3fHigh· 7.5JLine3 Telnet server: Unauthenticated Remote Memory Exhaustion via Unbounded Telnet NEW-ENVIRON Variables
JLine3 Telnet server: Unauthenticated Remote Memory Exhaustion via Unbounded Telnet NEW-ENVIRON Variables