{"id":"CVE-2026-94002","title":"Apache MINA SSHD: Memory exhaustion in SFTP client via unsolicited SFTP replies","summary":"Possible memory exhaustion in SFTP clients (DefaultSftpClient) in component sshd-sftp in Apache MINA SSHD versions 0.9.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5.\n\n\n\n\nApache \nMINA SSHD is a Java library for client-side and server-side SSH. The…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cvssSource":"cna","cwe":["CWE-770"],"vendor":"Apache Software Foundation","product":"org.apache.sshd:sshd-sftp","affected":["org.apache.sshd:sshd-sftp >= 0.9.0 < 2.20.0","org.apache.sshd:sshd-sftp >= 3.0.0-M1 < 3.0.0-M6"],"published":"2026-09-30","updated":"2026-09-30","sourceUpdated":"2026-09-30T09:37:01.922Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2026-94002","references":[{"url":"https://lists.apache.org/thread.html/x2cb00kh4qvsq145tj2w4g3toy8cybld"}],"tags":["cve.org"],"ingestedAt":"2026-09-30T10:01:20.475Z","slug":"CVE-2026-94002","body":"## Overview\n\nPossible memory exhaustion in SFTP clients (DefaultSftpClient) in component sshd-sftp in Apache MINA SSHD versions 0.9.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5.\n\n\n\n\nApache \nMINA SSHD is a Java library for client-side and server-side SSH. The sshd-sftp component provides support for SFTP.\n\n\n\n\nThe SFTP client implementation, when receiving a reply, did not check that this reply corresponded to a request sent earlier. Unsolicited replies would be stored but never consumed. A malicious server could keep sending unsolicited replies until available memory in the client was exhausted.\n\n\n\n\nUsers are recommended to upgrade to version 2.20.0 or 3.0.0-M6, which fix this issue.\n\n## Affected\n\n- `org.apache.sshd:sshd-sftp >= 0.9.0 < 2.20.0`\n- `org.apache.sshd:sshd-sftp >= 3.0.0-M1 < 3.0.0-M6`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}