org.apache.sshd:sshd-core vulnerabilities
CVEs whose affected-version data names the org.apache.sshd:sshd-core package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-93994High· 8.1Apache MINA SSHD: Repeated-publickey policy bypass on server
Apache MINA SSHD is a Java library for client-side and server-side SSH. SSH servers can be configured to require multi-authentication schemes, for instance two different public keys, not just one. In OpenSSH, this would be done by settin…
▾ TwilightApache Software Foundation · org.apache.sshd:sshd-corevia CVEORG
CVE-2026-77185Critical· 9.1Apache MINA SSHD: Asynchronous authentication can bypass signature verification
Authentication bypass in sshd-core in Apache MINA SSHD versions 2.0.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5 for a certain (presumed rare) way to implement an SSH server. Apache MINA SSHD is a Java library for client- and server-side SSH…
▾ MidnightApache Software Foundation · org.apache.sshd:sshd-corevia CVEORG