🔐 CVE Alert

CVE-2026-56452

HIGH 7.5

Apache MINA SSHD: Path traversal in SCP file reception

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th

Path traversal in the sshd-scp component of Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side and server-side SSH. The implementation of receiving files or directories via SCP did not validate filenames in SCP "C" or "D" commands. A malicious sender could send filenames containing paths, resulting in files to be written in attacker-controlled places. The issue affects only * applications that use no longer supported Apache MINA SSHD versions < 2.0.0 and use the SCP functions to receive files, * or applications using sshd-scp in Apache MINA SSHD >= 2.0.0 to receive files. Applications using Apache MINA SSHD >= 2.0.0 not using sshd-scp are not affected. The issue is fixed in Apache MINA 2.19.0 and 3.0.0-M5. Affected applications are advised to upgrade to these versions.

CWE CWE-22 CWE-73
Vendor apache software foundation
Product apache mina sshd
Published Jul 20, 2026
Last Updated Jul 20, 2026
Stay Ahead of the Next One

Get instant alerts for apache software foundation apache mina sshd

Be the first to know when new high vulnerabilities affecting apache software foundation apache mina sshd are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
None

Affected Versions

Apache Software Foundation / Apache MINA SSHD
0 ≤ 2.18.0 3.0.0-M1 ≤ 3.0.0-M4

References

NVD ↗ CVE.org ↗ EPSS Data ↗
lists.apache.org: https://lists.apache.org/thread/xgoqvmksmd94fsqnzqjdtfjxf35os9no openwall.com: http://www.openwall.com/lists/oss-security/2026/07/20/15

Credits

Unbbal