{"id":"CVE-2026-94029","title":"Apache MINA SSHD: Memory exhaustion in SFTP v6 check-file-name/check-file-handle extension","summary":"Server-side memory exhaustion in Apache MINA SSHD 1.0.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5, component sshd-sftp, in the SFTP v6 check-file-name/check-file-handle extension. Apache MINA SSHD is a Java library for client-side and server-si…","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cvssSource":"cna","cwe":["CWE-770"],"vendor":"Apache Software Foundation","product":"org.apache.sshd:sshd-sftp","affected":["org.apache.sshd:sshd-sftp >= 1.0.0 < 2.20.0","org.apache.sshd:sshd-sftp >= 3.0.0-M1 < 3.0.0-M6"],"published":"2026-09-30","updated":"2026-09-30","sourceUpdated":"2026-09-30T09:35:51.711Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2026-94029","references":[{"url":"https://lists.apache.org/thread.html/ytbl4rwby62xl7llm3wp7k975wwdx99t"}],"tags":["cve.org"],"ingestedAt":"2026-09-30T10:01:20.473Z","slug":"CVE-2026-94029","body":"## Overview\n\nServer-side memory exhaustion in Apache MINA SSHD 1.0.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5, component sshd-sftp, in the SFTP v6 check-file-name/check-file-handle extension. Apache MINA SSHD is a Java library for client-side and server-side SSH.\n\n\n\n\nUsing a very small \"block size\" (for instance 256, which is the minimum) on a huge file generates many (file size / block size) hashes. The resulting SFTP reply message was accumulated fully in memory server-side, which could, with a suitably large (possibly sparse) file exhaust the server-side memory, taking down the server.\n\n\n\n\nUsers are recommended to upgrade to version 2.20.0 or 3.0.0-M6, which fix this issue by imposing a maximum limit on the size of the reply. Many SFTP implementations have a general limit on the size of SFTP messages anyway; typically 256kB as in OpenSSH or also in Apache MINA SSHD.\n\n## Affected\n\n- `org.apache.sshd:sshd-sftp >= 1.0.0 < 2.20.0`\n- `org.apache.sshd:sshd-sftp >= 3.0.0-M1 < 3.0.0-M6`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}