Uncontrolled Resource Consumption in Apache MINA SSHD by Apache
CVE-2026-93996
6.5MEDIUM
What is CVE-2026-93996?
The sshd-scp component of Apache MINA SSHD fails to limit the length of SCP protocol lines, allowing for potential memory exhaustion. A malicious peer can send excessively long commands which, due to the lack of termination checks, lead to memory being allocated indefinitely. This can result in an OutOfMemoryError, causing crashes in applications utilizing this library. It is crucial for users to upgrade to versions 2.20.0 or 3.0.0-M6, which implement safeguards against such excessive resource allocation by setting limits on the lengths of SCP protocol lines.
Affected Version(s)
Apache MINA SSHD 0 < 2.20.0
Apache MINA SSHD 3.0.0-M1 < 3.0.0-M6