CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-56740

highCVSS 7.5covered by 2 sourcesfirst seen 2026-06-18
Summary The JLine3 Telnet server (remote-telnet module) does not limit the number of environment variables a client may inject via the Telnet NEW-ENVIRON option. An unauthenticated attacker can flood the server with a large number of unique variable pairs before sending the terminating IAC SE byte, exhausting JVM heap memory and causing an OutOfMemoryError (denial of service). Approximately 3–4 MB of network traffic is sufficient to consume a 512 MB JVM heap. Details TelnetIO.readNEVariables() (TelnetIO.java:1127-1180) processes incoming NEW-ENVIRON variable pairs in a loop and stores each pair in a HashMap held by ConnectionData: // TelnetIO.java:1139-1178 boolean cont = true; if (i == NE_VAR || i == NE_USERVAR) { do { switch (readNEVariableName(sbuf)) { case NE_VAR_OK: TelnetIO.this.connectionData.getEnvironment().put(str, sbuf.toString()); // ← no per-connection count limit break; case NE_VAR_UNDEFINED: break; // cont remains true, loop continues } } while (cont); // cont is never set to false; only exits via return } The variable accumulator map is a plain HashMap initialized with capacity 20 and no maximum size: // ConnectionData.java:98 environment = new HashMap<String, String>(20); Per-variable limits exist (name: max 50 chars, value: max 1000 chars), but there is no cap on the *count* of variables. Each map entry occupies approximately 2 KB of heap (String headers + Map.Entry + backing char arrays). On a JVM with a 512 MB heap, approximately 250,000 unique entries trigger an OutOfMemoryError. Network cost: using sequential 1-byte names (e.g., \x01, \x02, ...) and 1-byte values, each variable pair requires roughly 13 protocol bytes. Sending 250,000 pairs requires only ~3.25 MB of network traffic — feasible in seconds over any reasonable network connection. No authentication is required. NEW-ENVIRON negotiation occurs before login. Affected source files: - remote-telnet/src/main/java/org/jline/builtins/telnet/TelnetIO.java lines 1127-1180 - remote-te

⚡ Watch CVE-2026-56740

Get an email if CVE-2026-56740 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-56740

CVE.org record

Embed the live status

CVE-2026-56740 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-56740 status](https://www.csirts.com/badge/CVE-2026-56740)](https://www.csirts.com/cve/CVE-2026-56740)