---
id: CVE-2026-94002
title: >-
  Possible memory exhaustion in SFTP clients (DefaultSftpClient) in component
  sshd-sftp in Apache MINA SSHD versions 0.9.0 to 2.19.0 and 3.0.0-M1 to
  3.0.0-M5.





  Apache 

  MINA SSHD is a Java library for client-side and server-side SSH
summary: >-
  Possible memory exhaustion in SFTP clients (DefaultSftpClient) in component
  sshd-sftp in Apache MINA SSHD versions 0.9.0 to 2.19.0 and 3.0.0-M1 to
  3.0.0-M5.





  Apache 

  MINA SSHD is a Java library for client-side and server-side SSH. The…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-770
vendor: Apache Software Foundation
product: 'org.apache.sshd:sshd-sftp'
affected:
  - 'org.apache.sshd:sshd-sftp >= 0.9.0 < 2.20.0'
  - 'org.apache.sshd:sshd-sftp >= 3.0.0-M1 < 3.0.0-M6'
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T16:13:13.493'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-94002'
references:
  - url: 'https://lists.apache.org/thread.html/x2cb00kh4qvsq145tj2w4g3toy8cybld'
    label: security@apache.org
  - url: 'http://www.openwall.com/lists/oss-security/2026/09/29/36'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-94002.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-94002'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2543859'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-94002'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-94002'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
epss: 0.00385
epssPercentile: 0.30078
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-30T14:31:35.789900Z'
ingestedAt: '2026-09-30T10:01:20.475Z'
---

## Overview

Possible memory exhaustion in SFTP clients (DefaultSftpClient) in component sshd-sftp in Apache MINA SSHD versions 0.9.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5.




Apache 
MINA SSHD is a Java library for client-side and server-side SSH. The sshd-sftp component provides support for SFTP.




The SFTP client implementation, when receiving a reply, did not check that this reply corresponded to a request sent earlier. Unsolicited replies would be stored but never consumed. A malicious server could keep sending unsolicited replies until available memory in the client was exhausted.




Users are recommended to upgrade to version 2.20.0 or 3.0.0-M6, which fix this issue.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **Red Hat VEX** · Important · affected: Red Hat build of Apache Camel 4 for Quarkus 3, Red Hat build of Apache Camel for Spring Boot 4, Red Hat build of Apicurio Registry 3, Red Hat Fuse 7 · no fix planned: Red Hat build of Apache Camel 4 for Quarkus 3, Red Hat build of Apache Camel for Spring Boot 4, Red Hat build of Apicurio Registry 3, Red Hat Fuse 7 · updated 2026-09-30 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-94002.json)
