Apache MINA SSHD: resource exhaustion
High7.5CVE-2026-94002 · Published Sep 30, 2026
Possible memory exhaustion in SFTP clients (DefaultSftpClient) in component sshd-sftp in Apache MINA SSHD versions 0.9.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5. Apache MINA SSHD is a Java library for client-side and server-side SSH. The sshd-sftp component provides support for SFTP. The SFTP client implementation, when receiving a reply, did not check that this reply corresponded to a request sent earlier. Unsolicited replies would be stored but never consumed. A malicious server could keep sending unsolicited replies until available memory in the client was exhausted. Users are recommended to upgrade to version 2.20.0 or 3.0.0-M6, which fix this issue.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Apache MINA SSHD Product | >= 0.9.0, < 2.20.0 | 2.20.0 |
| >= 3.0.0-M1, < 3.0.0-M6 | 3.0.0-M6 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-770
More Apache Software Foundation advisories
All Apache Software Foundation| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 30 | Apache WSS4J: integer overflow | High7.5 | 4.0.2+2 more |
| Sep 30 | Apache WSS4J: insufficient authenticity check | Critical9.1 | 4.0.2+2 more |
| Sep 30 | Apache WSS4J: protection mechanism failure | High7.5 | 4.0.2+2 more |
| Sep 30 | Apache WSS4J: authentication bypass by spoofing | Medium4.8 | 4.0.2+2 more |
| Sep 30 | Apache WSS4J: expression injection | Critical9.1 | 4.0.2+2 more |
| Sep 30 | Apache WSS4J: authentication bypass | Critical9.8 | 4.0.2+2 more |