Severity: moderate 
    CVSS 3.1: 7.5 (high) CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected versions:

- Apache MINA SSHD 0.9.0 before 2.20.0
- Apache MINA SSHD 3.0.0-M1 before 3.0.0-M6

Description:

Possible memory exhaustion in SFTP clients (DefaultSftpClient) in component 
sshd-sftp in Apache MINA SSHD versions 0.9.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5.




Apache 
MINA SSHD is a Java library for client-side and server-side SSH. The sshd-sftp 
component provides support for SFTP.




The SFTP client implementation, when receiving a reply, did not check that this 
reply corresponded to a request sent earlier. Unsolicited replies would be 
stored but never consumed. A malicious server could keep sending unsolicited 
replies until available memory in the client was exhausted.




Users are recommended to upgrade to version 2.20.0 or 3.0.0-M6, which fix this 
issue.

Credit:

Ho1aAs <[email protected]> (finder)

References:

https://mina.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-94002

Reply via email to