CVE-2026-93995
Received Received - Intake

Improper Input Validation in Apache MINA SSHD sshd-git

Vulnerability report for CVE-2026-93995, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: Apache Software Foundation

Description

Improper input validation in sshd-git in Apache MINA SSHD, versions up to 2.19.0 and 3.0.0-M1 to 3.0.0-M5. Apache MINA SSHD is a Java library for client-side and server-side SSH. Component org.apache.sshd:sshd-git provides though class GitPgmCommandFactory a way to configure an Apache MINA SSHD server such that authenticated SSH clients can remotely execute git commands via the JGit library on git repositories stored on the server. InΒ CVE-2026-58624 this mechanism was restricted to only a few git commands, including "git archive" without "--output" or "-o" options such that the resulting archive would not be written on the server but instead sent back to the client over the SSH connection. The fix done forΒ CVE-2026-58624 was insufficient as it missed removing the single-argument "-o=file.zip"Β version of the command parameterΒ from the "archive" command. Users are recommended to upgrade to version 2.20.0 or 3.0.0-M6, which fix this issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 7 associated CPEs
Vendor Product Version / Range
apache minasshd to 2.19.0 (inc)
apache minasshd From 3.0.0-M1 (inc) to 3.0.0-M5 (inc)
apache minasshd 2.20.0
apache minasshd 3.0.0-M6
apache mina to 2.19.0 (inc)
apache mina From 3.0.0-M1 (inc) to 3.0.0-M5 (inc)
apache mina sshd-git

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-20 The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an improper input validation flaw in Apache MINA SSHD's sshd-git component. It allows authenticated SSH clients to remotely execute git commands on server repositories. The issue was partially fixed in CVE-2026-58624 but the fix missed removing the single-argument '-o=file.zip' version of the 'archive' command parameter, allowing attackers to write files to the server.

Detection Guidance

This vulnerability involves improper input validation in Apache MINA SSHD's sshd-git component, allowing remote command execution via git archive commands. To detect it, check the version of Apache MINA SSHD in use. If it is 2.19.0 or 3.0.0-M1 to 3.0.0-M5, the system is vulnerable. Commands to check the version include 'mvn dependency:tree' for Maven projects or inspecting the JAR file metadata.

Impact Analysis

An attacker with SSH access could exploit this to write arbitrary files to the server filesystem. This could lead to remote code execution, data exfiltration, or server compromise. The impact depends on server configuration and user permissions.

Compliance Impact

This vulnerability does not directly impact compliance with GDPR or HIPAA as it involves improper input validation in an SSH library for executing git commands. However, if exploited, it could allow unauthorized access to sensitive data stored in git repositories, potentially violating data protection requirements under GDPR or HIPAA depending on the data processed.

Mitigation Strategies

Upgrade Apache MINA SSHD to version 2.20.0 or 3.0.0-M6 to address the improper input validation issue in sshd-git.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-93995. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart