PT-2026-103109 · Apache · Apache Mina Sshd

·

CVE-2026-94029

·

Published

2026-09-30

·

Updated

2026-10-01

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Apache MINA SSHD versions 1.0.0 through 2.19.0 Apache MINA SSHD versions 3.0.0-M1 through 3.0.0-M5
Description Server-side memory exhaustion occurs in the sshd-sftp component within the SFTP v6 check-file-name/check-file-handle extension. When a very small block size is used on a large file, the system generates an excessive number of hashes. Because the resulting SFTP reply message is accumulated entirely in the server memory, a sufficiently large or sparse file can exhaust available memory and cause the server to crash.
Recommendations Upgrade versions 1.0.0 through 2.19.0 to version 2.20.0. Upgrade versions 3.0.0-M1 through 3.0.0-M5 to version 3.0.0-M6.

Fix

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-94029
OPENSUSE-SU-2026:11940-1

Affected Products

Apache Mina Sshd