Memory Exhaustion Vulnerability in Apache MINA SSHD SFTP Client
CVE-2026-94002
7.5HIGH
What is CVE-2026-94002?
The Apache MINA SSHD library features an SFTP client that contains a vulnerability where it fails to verify that received replies correspond to prior requests. This oversight allows a malicious server to continuously send unsolicited replies, ultimately exhausting the client's memory resources. It is advisable for users to upgrade to version 2.20.0 or 3.0.0-M6 to mitigate this issue effectively.
Affected Version(s)
Apache MINA SSHD 0.9.0 < 2.20.0
Apache MINA SSHD 3.0.0-M1 < 3.0.0-M6