PT-2026-103107 · Apache · Apache Mina Sshd
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Apache MINA SSHD versions prior to 2.20.0
Apache MINA SSHD versions 3.0.0-M1 through 3.0.0-M5
Description
Uncontrolled resource consumption exists in the
sshd-scp component, which provides a Java implementation of the Secure Copy Protocol (SCP). The SCP command protocol is line-oriented and relies on Line Feed (LF) characters to terminate lines. Because the protocol handler does not impose a limit on the length of these lines, a malicious peer can send a continuous sequence of characters without an LF terminator. This forces the receiver to allocate excessive memory to store the command, leading to memory exhaustion and an OutOfMemoryError that crashes the application.Recommendations
Upgrade to version 2.20.0.
Upgrade to version 3.0.0-M6.
Fix
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Mina Sshd