Apache
MINA SSHD is a Java library for client-side and server-side SSH. The sshd-sftp component provides support for SFTP.
The SFTP client implementation, when receiving a reply, did not check that this reply corresponded to a request sent earlier. Unsolicited replies would be stored but never consumed. A malicious server could keep sending unsolicited replies until available memory in the client was exhausted.
Users are recommended to upgrade to version 2.20.0 or 3.0.0-M6, which fix this issue.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 01 Oct 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Wed, 30 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 30 Sep 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache mina Sshd |
|
| Vendors & Products |
Apache
Apache mina Sshd |
Wed, 30 Sep 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 30 Sep 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Possible memory exhaustion in SFTP clients (DefaultSftpClient) in component sshd-sftp in Apache MINA SSHD versions 0.9.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5. Apache MINA SSHD is a Java library for client-side and server-side SSH. The sshd-sftp component provides support for SFTP. The SFTP client implementation, when receiving a reply, did not check that this reply corresponded to a request sent earlier. Unsolicited replies would be stored but never consumed. A malicious server could keep sending unsolicited replies until available memory in the client was exhausted. Users are recommended to upgrade to version 2.20.0 or 3.0.0-M6, which fix this issue. | |
| Title | Apache MINA SSHD: Memory exhaustion in SFTP client via unsolicited SFTP replies | |
| Weaknesses | CWE-770 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-09-30T14:31:45.869Z
Reserved: 2026-09-19T14:20:51.289Z
Link: CVE-2026-94002
Updated: 2026-09-30T10:14:15.211Z
Status : Awaiting Analysis
Published: 2026-09-30T10:17:17.877
Modified: 2026-09-30T16:13:13.493
Link: CVE-2026-94002
OpenCVE Enrichment
Updated: 2026-09-30T13:00:14Z