JLine 4.2.1 is a security patch release addressing two denial-of-service vulnerabilities in the remote-telnet module.
🔒 Security Fixes
- fix: clamp NAWS terminal dimensions to prevent CPU exhaustion (GHSA-2r2c-cx56-8933)
- fix: cap NEW-ENVIRON variable count to prevent heap exhaustion (GHSA-47qp-hqvx-6r3f)
🐛 Bug Fixes
📦 Dependency updates
- chore: Bump com.diffplug.spotless:spotless-maven-plugin from 3.6.0 to 3.7.0 (#1973) @dependabot[bot]