Junglewise Threat Intelligence

CVE-2026-82604: Barebones BBEdit uncontrolled recursion in Java Language Module

CVE-2026-82604 · Severity: medium · CVSS 4.3 · Published 2026-08-31

Executive brief

BBEdit is a text editor widely used by developers for code editing and manipulation. A flaw in the Java Language Module component can trigger uncontrolled recursion, causing the application to exhaust system resources and become unresponsive. An attacker can exploit this remotely by crafting malicious input, leading to a denial of service that impacts developer productivity and system availability.

Technical details

The vulnerability is an uncontrolled recursion flaw in the Java Language Module component of BBEdit, triggered through an unknown function within this module. The attack is network-reachable and does not require authentication or user interaction beyond processing of crafted input. An attacker can exploit this to cause stack exhaustion or infinite loops, resulting in denial of service by exhausting system resources. BBEdit versions up to 15.5.5 are affected; upgrading to version 16.0 or later resolves the issue.

Affected products

  • Barebones BBEdit up to 15.5.5

Timeline

  • 2026-08-31: disclosed

References