JLine is a Java library for handling console input. Prior to 3.30.14, 4.0.16, and 4.2.1, the JLine3 Telnet server remote-telnet module does not apply an upper bound to terminal dimensions received via the Telnet NAWS option, and TelnetIO.handleNAWS() in TelnetIO.java:856-879 reads client-supplied width and height as 16-bit unsigned integers and passes values such as 65535x65535 to setTerminalGeometry(), allowing an unauthenticated remote attacker to repeatedly alternate values and trigger continuous expensive rendering work that causes CPU exhaustion and denial of service. This issue is fixed in versions 3.30.14, 4.0.16, and 4.2.1.
History

Tue, 18 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:jline:jline:*:*:*:*:*:*:*:*

Tue, 28 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Jline
Jline jline
Vendors & Products Jline
Jline jline

Mon, 20 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 17 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Description JLine is a Java library for handling console input. Prior to 3.30.14, 4.0.16, and 4.2.1, the JLine3 Telnet server remote-telnet module does not apply an upper bound to terminal dimensions received via the Telnet NAWS option, and TelnetIO.handleNAWS() in TelnetIO.java:856-879 reads client-supplied width and height as 16-bit unsigned integers and passes values such as 65535x65535 to setTerminalGeometry(), allowing an unauthenticated remote attacker to repeatedly alternate values and trigger continuous expensive rendering work that causes CPU exhaustion and denial of service. This issue is fixed in versions 3.30.14, 4.0.16, and 4.2.1.
Title JLine: Unauthenticated Remote DoS via Unbounded Telnet NAWS Terminal Geometry
Weaknesses CWE-400
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2026-07-17T21:15:14.732Z

Updated: 2026-07-20T15:21:23.382Z

Reserved: 2026-06-22T19:17:28.959Z

Link: CVE-2026-56741

cve-icon Vulnrichment

Updated: 2026-07-20T15:21:18.349Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-17T22:17:57.317

Modified: 2026-08-18T15:17:51.030

Link: CVE-2026-56741

cve-icon Redhat

No data.