Path Traversal Vulnerability in Apache MINA SSHD for SSH File Transfers
CVE-2026-56452
7.5HIGH
What is CVE-2026-56452?
A security flaw has been identified in the sshd-scp component of Apache MINA SSHD, a Java library used for SSH communication. The vulnerability arises from the failure to validate filenames in SCP commands, allowing a malicious sender to manipulate file paths. Consequently, this could result in files being written to unauthorized locations within the server. The issue specifically impacts applications that utilize unsupported versions of Apache MINA SSHD before 2.0.0, as well as those employing the sshd-scp functionality in versions 2.0.0 and upwards. To mitigate risks, upgrading to Apache MINA versions 2.19.0 or 3.0.0-M5 is strongly recommended.
Affected Version(s)
Apache MINA SSHD 0 <= 2.18.0
Apache MINA SSHD 3.0.0-M1 <= 3.0.0-M4