CVE-2026-93995Medium· 6.5▾ SunlitImproper input validation in sshd-git in Apache MINA SSHD, versions up to 2.19.0 and 3.0.0-M1 to 3.0.0-M5. Apache MINA SSHD is a Java library for client-side and server-side SSH. Component org.apache.sshd:sshd-git provides though cl…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Improper input validation in sshd-git in Apache MINA SSHD, versions up to 2.19.0 and 3.0.0-M1 to 3.0.0-M5. Apache MINA SSHD is a Java library for client-side and server-side SSH.
Component org.apache.sshd:sshd-git provides though class GitPgmCommandFactory a way to configure an Apache MINA SSHD server such that authenticated SSH clients can remotely execute git commands via the JGit library on git repositories stored on the server. In CVE-2026-58624 this mechanism was restricted to only a few git commands, including "git archive" without "--output" or "-o" options such that the resulting archive would not be written on the server but instead sent back to the client over the SSH connection.
The fix done for CVE-2026-58624 was insufficient as it missed removing the single-argument "-o=file.zip" version of the command parameter from the "archive" command.
Users are recommended to upgrade to version 2.20.0 or 3.0.0-M6, which fix this issue.
org.apache.sshd:sshd-git < 2.20.0org.apache.sshd:sshd-git >= 3.0.0-M1 < 3.0.0-M6Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-82441Critical· 9.1Description A submitted topology carries two lists of blobstore keys, `dependency_jars` and `dependency_artifacts`, which the client fills in after uploading the corresponding blobs
CVE-2026-94052Critical· 9.1Apache MINA SSHD: LDAP password authentication ineffective
CVE-2026-94002High· 7.5Apache MINA SSHD: Memory exhaustion in SFTP client via unsolicited SFTP replies
CVE-2026-93996Medium· 6.5Apache MINA SSHD: Memory exhaustion DoS via unbounded SCP command line read
CVE-2026-94053Critical· 9.1Apache MINA SSHD: LDAP injection in sshd-ldap
CVE-2026-94029Medium· 6.5Apache MINA SSHD: Memory exhaustion in SFTP v6 check-file-name/check-file-handle extension