🔐 CVE Alert

CVE-2026-94029

MEDIUM 6.5

Apache MINA SSHD: Memory exhaustion in SFTP v6 check-file-name/check-file-handle extension

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

Server-side memory exhaustion in Apache MINA SSHD 1.0.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5, component sshd-sftp, in the SFTP v6 check-file-name/check-file-handle extension. Apache MINA SSHD is a Java library for client-side and server-side SSH. Using a very small "block size" (for instance 256, which is the minimum) on a huge file generates many (file size / block size) hashes. The resulting SFTP reply message was accumulated fully in memory server-side, which could, with a suitably large (possibly sparse) file exhaust the server-side memory, taking down the server. Users are recommended to upgrade to version 2.20.0 or 3.0.0-M6, which fix this issue by imposing a maximum limit on the size of the reply. Many SFTP implementations have a general limit on the size of SFTP messages anyway; typically 256kB as in OpenSSH or also in Apache MINA SSHD.

CWE CWE-770
Vendor apache software foundation
Product apache mina sshd
Published Sep 30, 2026
Last Updated Sep 30, 2026
Stay Ahead of the Next One

Get instant alerts for apache software foundation apache mina sshd

Be the first to know when new medium vulnerabilities affecting apache software foundation apache mina sshd are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High

Affected Versions

Apache Software Foundation / Apache MINA SSHD
1.0.0 < 2.20.0 3.0.0-M1 < 3.0.0-M6

References

NVD ↗ CVE.org ↗ EPSS Data ↗
lists.apache.org: https://lists.apache.org/thread.html/ytbl4rwby62xl7llm3wp7k975wwdx99t openwall.com: http://www.openwall.com/lists/oss-security/2026/09/29/37

Credits

Ho1aAs <[email protected]>