CVE-2026-94002
Received Received - Intake

Memory Exhaustion in Apache MINA SSHD SFTP Client

Vulnerability report for CVE-2026-94002, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: Apache Software Foundation

Description

Possible memory exhaustion in SFTP clients (DefaultSftpClient) in component sshd-sftp in Apache MINA SSHD versions 0.9.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5. Apache MINA SSHD is a Java library for client-side and server-side SSH. The sshd-sftp component provides support for SFTP. The SFTP client implementation, when receiving a reply, did not check that this reply corresponded to a request sent earlier. Unsolicited replies would be stored but never consumed. A malicious server could keep sending unsolicited replies until available memory in the client was exhausted. Users are recommended to upgrade to version 2.20.0 or 3.0.0-M6, which fix this issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
apache mina From 3.0.0-M1 (inc) to 3.0.0-M6 (exc)
apache mina From 0.9.0 (inc) to 2.20.0 (exc)
apache mina From 3.0.0 (inc) to 3.0.0-M6 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a memory exhaustion issue in SFTP clients (DefaultSftpClient) within Apache MINA SSHD versions 0.9.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5. The SFTP client fails to verify if received replies correspond to sent requests, storing unsolicited replies without consuming them. A malicious server could exploit this by sending endless unsolicited replies, eventually exhausting the client's memory.

Detection Guidance

This vulnerability involves memory exhaustion in SFTP clients due to unsolicited replies. Detection requires monitoring memory usage and network traffic for unexpected SFTP server responses. Check if your system uses Apache MINA SSHD versions 0.9.0 to 2.19.0 or 3.0.0-M1 to 3.0.0-M5. Use commands like 'jcmd <pid> VM.native_memory' to monitor memory or 'netstat -tulnp | grep sshd' to inspect SSH/SFTP connections.

Impact Analysis

This vulnerability could cause your SFTP client to crash or become unresponsive due to memory exhaustion. If exploited by a malicious server, it may lead to denial-of-service conditions, disrupting file transfer operations and potentially affecting dependent applications relying on the SFTP client.

Compliance Impact

This vulnerability could indirectly impact compliance with standards like GDPR or HIPAA by enabling denial-of-service attacks that disrupt system availability. Memory exhaustion in SFTP clients may lead to service unavailability, potentially violating availability requirements in these regulations.

Mitigation Strategies

Upgrade Apache MINA SSHD to version 2.20.0 or 3.0.0-M6 or later to fix the issue. If upgrading is not immediately possible, restrict access to trusted SFTP servers or implement network-level controls to limit unsolicited traffic.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-94002. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart