Server-Side Memory Exhaustion in Apache MINA SSHD by The Apache Software Foundation
CVE-2026-94029
6.5MEDIUM
What is CVE-2026-94029?
The server-side memory exhaustion vulnerability in Apache MINA SSHD affects versions 1.0.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5 in the sshd-sftp component. This issue arises when using a very small block size during file transfer, resulting in excessive server-side memory usage due to the accumulation of SFTP reply messages. Consequently, a large file can exhaust server memory resources, potentially leading to server downtime. It is advised to upgrade to version 2.20.0 or 3.0.0-M6, which address the vulnerability by enforcing limits on reply size.
Affected Version(s)
Apache MINA SSHD 1.0.0 < 2.20.0
Apache MINA SSHD 3.0.0-M1 < 3.0.0-M6