PT-2026-103108 · Apache · Apache Mina Sshd
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Apache MINA SSHD versions 0.9.0 through 2.19.0
Apache MINA SSHD versions 3.0.0-M1 through 3.0.0-M5
Description
The
sshd-sftp component of the Apache MINA SSHD Java library contains a flaw in the DefaultSftpClient implementation. When receiving a reply, the client fails to verify if the response corresponds to a previously sent request. Consequently, unsolicited replies are stored without being consumed, allowing a malicious server to send continuous unsolicited responses until the client's available memory is exhausted, leading to memory exhaustion.Recommendations
Upgrade versions 0.9.0 through 2.19.0 to version 2.20.0.
Upgrade versions 3.0.0-M1 through 3.0.0-M5 to version 3.0.0-M6.
Fix
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Mina Sshd