{"id":"GHSA-r2xf-8xr9-62gw","summary":"JLine: ReDoS in Built-in grep Command Amplified by Automatic `.*` Wrapping","details":"### Summary\n\nThe JLine3 built-in `grep` command wraps the user-supplied regular expression with\n`.*` before compiling it with Java's backtracking regex engine. This amplifies\ncatastrophic backtracking and allows a short pattern such as `(a+)+b` to hang the\ncommand thread on non-matching input. In environments that expose the JLine shell to\nremote users, this is a denial-of-service issue.\n\n### Details\n\nIn `builtins/src/main/java/org/jline/builtins/PosixCommands.java`, the grep\nimplementation rewrites the user pattern before compilation:\n\n```java\nString regex = args.remove(0);\nString regexp = regex;\nif (opt.isSet(\"word-regexp\")) {\n    regexp = \"\\\\b\" + regexp + \"\\\\b\";\n}\nif (opt.isSet(\"line-regexp\")) {\n    regexp = \"^\" + regexp + \"$\";\n} else {\n    regexp = \".*\" + regexp + \".*\";\n}\n```\n\nThe transformed pattern is compiled with `Pattern.compile(...)` and then used to test\neach input line. For a payload such as `(a+)+b`, the automatic `.*` prefix and suffix\nincrease the backtracking search space substantially.\n\nAffected source location:\n- `builtins/src/main/java/org/jline/builtins/PosixCommands.java`\n- `grep(...)`\n\n### PoC\n\n1. Create a file containing a long run of `a` characters:\n\n```sh\nprintf 'aaaaaaaaaaaaaaaaaaaaaaa\\n' \u003e /tmp/testfile.txt\n```\n\n2. Run JLine3's built-in `grep` against that file:\n\n```sh\ngrep '(a+)+b' /tmp/testfile.txt\n```\n\nExpected result:\n- The command stops responding.\n- The executing thread consumes high CPU.\n\nReproduction environment:\n- JLine3 on x86_64 Linux\n- OpenJDK 25.0.2\n\n### Impact\n\nThis is a denial-of-service vulnerability caused by catastrophic regex backtracking.\nAny application embedding `org.jline:jline-builtins` and exposing the built-in `grep`\ncommand is impacted. In remote shell deployments, an attacker can occupy a worker\nthread indefinitely and repeat the attack across multiple sessions to reduce service\navailability for other users.\n\n### Suggested Fix\n\nThe preferred fix for the current git head is:\n- stop rewriting non-line-regexp searches as `.*...*`\n- use `Matcher.find()` for substring semantics\n- compile user patterns with a linear-time engine such as RE2/J\n\nSuggested patch:\n\n```diff\ndiff --git a/builtins/pom.xml b/builtins/pom.xml\n--- a/builtins/pom.xml\n+++ b/builtins/pom.xml\n@@\n         \u003cdependency\u003e\n+            \u003cgroupId\u003ecom.google.re2j\u003c/groupId\u003e\n+            \u003cartifactId\u003ere2j\u003c/artifactId\u003e\n+            \u003cversion\u003e1.8\u003c/version\u003e\n+        \u003c/dependency\u003e\n+        \u003cdependency\u003e\n             \u003cgroupId\u003eorg.jline\u003c/groupId\u003e\n             \u003cartifactId\u003ejline-reader\u003c/artifactId\u003e\n         \u003c/dependency\u003e\n\ndiff --git a/builtins/src/main/java/org/jline/builtins/PosixCommands.java b/builtins/src/main/java/org/jline/builtins/PosixCommands.java\n--- a/builtins/src/main/java/org/jline/builtins/PosixCommands.java\n+++ b/builtins/src/main/java/org/jline/builtins/PosixCommands.java\n@@\n-import java.util.regex.Pattern;\n+import com.google.re2j.Pattern;\n@@\n         if (opt.isSet(\"line-regexp\")) {\n             regexp = \"^\" + regexp + \"$\";\n-        } else {\n-            regexp = \".*\" + regexp + \".*\";\n         }\n@@\n-        boolean m = p.matcher(line).matches();\n+        boolean m = opt.isSet(\"line-regexp\")\n+                ? p.matcher(line).matches()\n+                : p.matcher(line).find();\n```\n\n### Credits\n\nThis issue was identified by Michał Majchrowicz and Marcin Wyczechowski, members of the AFINE Team.","aliases":["CVE-2026-77422"],"modified":"2026-09-23T18:28:35.110628250Z","published":"2026-09-23T18:12:35Z","database_specific":{"cwe_ids":["CWE-1333"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-09-23T18:12:35Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/jline/jline3/security/advisories/GHSA-r2xf-8xr9-62gw"},{"type":"WEB","url":"https://github.com/jline/jline3/pull/2012"},{"type":"WEB","url":"https://github.com/jline/jline3/pull/2018"},{"type":"WEB","url":"https://github.com/jline/jline3/commit/1d5fc3099e77938b971e197211cad2d4fbb17541"},{"type":"WEB","url":"https://github.com/jline/jline3/commit/341ee69ccc57b7733c1b40d6993219b64b3206ae"},{"type":"PACKAGE","url":"https://github.com/jline/jline3"},{"type":"WEB","url":"https://github.com/jline/jline3/releases/tag/4.3.1"},{"type":"WEB","url":"https://github.com/jline/jline3/releases/tag/jline-3.30.15"}],"affected":[{"package":{"name":"org.jline:jline-builtins","ecosystem":"Maven","purl":"pkg:maven/org.jline/jline-builtins"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.0.0"},{"fixed":"4.3.1"}]}],"versions":["4.0.0","4.0.10","4.0.11","4.0.12","4.0.13","4.0.14","4.0.15","4.0.16","4.0.2","4.0.3","4.0.4","4.0.5","4.0.6","4.0.7","4.0.8","4.0.9","4.1.0","4.1.1","4.1.2","4.1.3","4.2.0","4.2.1","4.3.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-r2xf-8xr9-62gw/GHSA-r2xf-8xr9-62gw.json"}},{"package":{"name":"org.jline:jline-builtins","ecosystem":"Maven","purl":"pkg:maven/org.jline/jline-builtins"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.0.0"},{"fixed":"3.30.15"}]}],"versions":["3.10.0","3.11.0","3.12.0","3.12.1","3.13.0","3.13.1","3.13.2","3.13.3","3.14.0","3.14.1","3.15.0","3.16.0","3.17.0","3.17.1","3.18.0","3.19.0","3.2.0","3.20.0","3.21.0","3.22.0","3.23.0","3.24.0","3.24.1","3.25.0","3.25.1","3.26.0","3.26.1","3.26.2","3.26.3","3.27.0","3.27.1","3.28.0","3.29.0","3.3.0","3.3.1","3.30.0","3.30.1","3.30.10","3.30.11","3.30.12","3.30.13","3.30.14","3.30.2","3.30.3","3.30.4","3.30.5","3.30.6","3.30.7","3.30.8","3.30.9","3.4.0","3.5.0","3.5.1","3.5.2","3.6.0","3.6.1","3.6.2","3.7.0","3.7.1","3.8.0","3.8.1","3.8.2","3.9.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-r2xf-8xr9-62gw/GHSA-r2xf-8xr9-62gw.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}