[Git][security-tracker-team/security-tracker][master] new jline issues

Moritz Muehlenhoff (@jmm) jmm at debian.org
Thu Sep 24 15:41:59 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
54cb2bd0 by Moritz Muehlenhoff at 2026-09-24T16:41:29+02:00
new jline issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -660,13 +660,33 @@ CVE-2026-77602 (OpenC3 COSMOS provides the functionality needed to send commands
 CVE-2026-77601 (OpenC3 COSMOS provides the functionality needed to send commands to an ...)
 	NOT-FOR-US: OpenC3 COSMOS
 CVE-2026-77423 (JLine is a Java library for handling console input. From 3.0.0 until 3 ...)
-	TODO: check
+	- jline3 <unfixed>
+	- jline2 <not-affected> (Less pager was introduced in 3.x)
+	- jline <not-affected> (Less pager was introduced in 3.x)
+	NOTE: https://github.com/jline/jline3/security/advisories/GHSA-2v9w-34q6-wpqx
+	NOTE: https://github.com/jline/jline3/pull/2018
+	NOTE: https://github.com/jline/jline3/commit/341ee69ccc57b7733c1b40d6993219b64b3206ae
 CVE-2026-77422 (JLine is a Java library for handling console input. From 3.0.0 until 3 ...)
-	TODO: check
+	- jline3 <unfixed>
+	- jline2 <not-affected> (Grep command was introduced in 3.x)
+	- jline <not-affected> (Grep command was introduced in 3.x)
+	NOTE: https://github.com/jline/jline3/security/advisories/GHSA-r2xf-8xr9-62gw
+	NOTE: https://github.com/jline/jline3/pull/2018
+	NOTE: https://github.com/jline/jline3/commit/341ee69ccc57b7733c1b40d6993219b64b3206ae
 CVE-2026-77421 (JLine is a Java library for handling console input. From 3.0.0 until 3 ...)
-	TODO: check
+	- jline3 <unfixed>
+	- jline2 <not-affected> (Nano editor was introduced in 3.x)
+	- jline <not-affected> (Nano editor was introduced in 3.x)
+	NOTE: https://github.com/jline/jline3/security/advisories/GHSA-ph9c-7hw9-vhhw
+	NOTE: https://github.com/jline/jline3/pull/2018
+	NOTE: https://github.com/jline/jline3/commit/341ee69ccc57b7733c1b40d6993219b64b3206ae
 CVE-2026-77420 (JLine is a Java library for handling console input. From 3.0.0 until 3 ...)
-	TODO: check
+	- jline3 <unfixed>
+	- jline2 <not-affected> (HISTORY_IGNORE was introduced in 3.x)
+	- jline <not-affected> (HISTORY_IGNORE was introduced in 3.x)
+	NOTE: https://github.com/jline/jline3/security/advisories/GHSA-5q95-hrpc-m3w3
+	NOTE: https://github.com/jline/jline3/pull/2018
+	NOTE: https://github.com/jline/jline3/commit/341ee69ccc57b7733c1b40d6993219b64b3206ae
 CVE-2026-77394 (OpenC3 COSMOS provides the functionality needed to send commands to an ...)
 	NOT-FOR-US: OpenC3 COSMOS
 CVE-2026-77285 (OpenBao is an open source identity-based secrets management system. Pr ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/54cb2bd03dca831de0d2c445888161a526cf8fb2

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/54cb2bd03dca831de0d2c445888161a526cf8fb2
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260924/6bd414f1/attachment.htm>


More information about the debian-security-tracker-commits mailing list