CVE-2026-94029
Received Received - Intake

Memory Exhaustion in Apache MINA SSHD SFTP Extension

Vulnerability report for CVE-2026-94029, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: Apache Software Foundation

Description

Server-side memory exhaustion in Apache MINA SSHD 1.0.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5, component sshd-sftp, in the SFTP v6 check-file-name/check-file-handle extension. Apache MINA SSHD is a Java library for client-side and server-side SSH. Using a very small "block size" (for instance 256, which is the minimum) on a huge file generates many (file size / block size) hashes. The resulting SFTP reply message was accumulated fully in memory server-side, which could, with a suitably large (possibly sparse) file exhaust the server-side memory, taking down the server. Users are recommended to upgrade to version 2.20.0 or 3.0.0-M6, which fix this issue by imposing a maximum limit on the size of the reply. Many SFTP implementations have a general limit on the size of SFTP messages anyway; typically 256kB as in OpenSSH or also in Apache MINA SSHD.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
apache mina to 2.19.0 (exc)
apache mina From 3.0.0-m1 (inc) to 3.0.0-m5 (exc)
apache mina sshd

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a server-side memory exhaustion vulnerability in Apache MINA SSHD versions 1.0.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5. It occurs in the SFTP v6 check-file-name/check-file-handle extension when a very small block size (like 256) is used on a large file. The server accumulates many hashes in memory, which can exhaust server resources and crash the system.

Detection Guidance

This vulnerability can be detected by monitoring for unusual memory usage on the SSH server running Apache MINA SSHD. Check for processes consuming excessive memory or frequent crashes. No specific commands are provided in the context.

Impact Analysis

If exploited, this vulnerability could cause the server to run out of memory and crash, leading to denial of service. Attackers could target servers processing large files with small block sizes, disrupting services and potentially causing data loss or downtime.

Compliance Impact

This vulnerability could lead to server crashes due to memory exhaustion, potentially causing service disruptions. For GDPR, this may impact availability of personal data processing systems. For HIPAA, it could disrupt healthcare services handling protected health information. Downtime may violate compliance requirements for data access and system reliability.

Mitigation Strategies

Upgrade Apache MINA SSHD to version 2.20.0 or 3.0.0-M6 or later to fix the issue. If upgrading is not possible, restrict access to the SFTP service or limit file sizes to prevent memory exhaustion.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-94029. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart