---
id: CVE-2026-94029
title: >-
  Apache MINA SSHD: Memory exhaustion in SFTP v6
  check-file-name/check-file-handle extension
summary: "Server-side memory exhaustion in Apache MINA SSHD 1.0.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5, component sshd-sftp, in the SFTP v6 check-file-name/check-file-handle extension.\_Apache MINA SSHD is a Java library for client-side and server-si…"
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
cvssSource: cna
cwe:
  - CWE-770
vendor: Apache Software Foundation
product: 'org.apache.sshd:sshd-sftp'
affected:
  - 'org.apache.sshd:sshd-sftp >= 1.0.0 < 2.20.0'
  - 'org.apache.sshd:sshd-sftp >= 3.0.0-M1 < 3.0.0-M6'
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T09:35:51.711Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-94029'
references:
  - url: 'https://lists.apache.org/thread.html/ytbl4rwby62xl7llm3wp7k975wwdx99t'
tags:
  - cve.org
ingestedAt: '2026-09-30T10:01:20.473Z'
---

## Overview

Server-side memory exhaustion in Apache MINA SSHD 1.0.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5, component sshd-sftp, in the SFTP v6 check-file-name/check-file-handle extension. Apache MINA SSHD is a Java library for client-side and server-side SSH.




Using a very small "block size" (for instance 256, which is the minimum) on a huge file generates many (file size / block size) hashes. The resulting SFTP reply message was accumulated fully in memory server-side, which could, with a suitably large (possibly sparse) file exhaust the server-side memory, taking down the server.




Users are recommended to upgrade to version 2.20.0 or 3.0.0-M6, which fix this issue by imposing a maximum limit on the size of the reply. Many SFTP implementations have a general limit on the size of SFTP messages anyway; typically 256kB as in OpenSSH or also in Apache MINA SSHD.

## Affected

- `org.apache.sshd:sshd-sftp >= 1.0.0 < 2.20.0`
- `org.apache.sshd:sshd-sftp >= 3.0.0-M1 < 3.0.0-M6`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
