org.apache.sshd:sshd-ldap vulnerabilities
CVEs whose affected-version data names the org.apache.sshd:sshd-ldap package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-94052Critical· 9.1Apache MINA SSHD: LDAP password authentication ineffective
A missing check in LdapPasswordAuthenticator in component sshd-ldap in Apache MINA SSHD versions 1.2.0 to 2.19.0 or 3.0.0-M1 to 3.0.0-M5 bypassed authentication checks. Apache MINA SSHD is a Java library for client-side and server-si…
▾ MidnightApache Software Foundation · org.apache.sshd:sshd-ldapvia CVEORG
CVE-2026-94053Critical· 9.1Apache MINA SSHD: LDAP injection in sshd-ldap
Authentication bypass via LDAP injection in component sshd-ldap in Apache MINA SSHD versions 1.2.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5. Apache MINA SSHD is a Java library for client-side and server-side SSH. The optional sshd-ldap co…
▾ MidnightApache Software Foundation · org.apache.sshd:sshd-ldapvia CVEORG