Uncontrolled Resource Consumption in Apache MINA SSHD by Apache
CVE-2026-93996

6.5MEDIUM

Key Information:

Vendor

Apache

Vendor
CVE Published:
30 September 2026

What is CVE-2026-93996?

The sshd-scp component of Apache MINA SSHD fails to limit the length of SCP protocol lines, allowing for potential memory exhaustion. A malicious peer can send excessively long commands which, due to the lack of termination checks, lead to memory being allocated indefinitely. This can result in an OutOfMemoryError, causing crashes in applications utilizing this library. It is crucial for users to upgrade to versions 2.20.0 or 3.0.0-M6, which implement safeguards against such excessive resource allocation by setting limits on the lengths of SCP protocol lines.

Affected Version(s)

Apache MINA SSHD 0 < 2.20.0

Apache MINA SSHD 3.0.0-M1 < 3.0.0-M6

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ho1aAs <xxy010605@gmail.com>
.