PT-2026-103107 · Apache · Apache Mina Sshd

·

CVE-2026-93996

·

Published

2026-09-30

·

Updated

2026-09-30

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Apache MINA SSHD versions prior to 2.20.0 Apache MINA SSHD versions 3.0.0-M1 through 3.0.0-M5
Description Uncontrolled resource consumption exists in the sshd-scp component, which provides a Java implementation of the Secure Copy Protocol (SCP). The SCP command protocol is line-oriented and relies on Line Feed (LF) characters to terminate lines. Because the protocol handler does not impose a limit on the length of these lines, a malicious peer can send a continuous sequence of characters without an LF terminator. This forces the receiver to allocate excessive memory to store the command, leading to memory exhaustion and an OutOfMemoryError that crashes the application.
Recommendations Upgrade to version 2.20.0. Upgrade to version 3.0.0-M6.

Fix

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-93996

Affected Products

Apache Mina Sshd