Sceawere
Vulnerability Detail
CVE-2026-93996UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Apache MINA SSHD Memory Exhaustion
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.5
- Creation Date
- 2h ago
- Vendor
- Apache Software Foundation
- Product
- Apache MINA SSHD
- Attack Type
- CWE-770 Allocation of resources without limits or throttling
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Uncontrolled resource consumption in component ssd-scp in Apache MINA SSHD versions up to 2.19.0 or 3.0.0-M1 to 3.0.0-M5. Apache MINA SSHD is a Java library for client-side and server-side SSH. Component sshd-scp of Apache MINA SSHD provides a Java implementation of SCP. The SCP command protocol is line-oriented with LF-terminated lines. The protocol handler in sshd-scp did not impose any limit on the length of such protocol lines. A malicious peer just sending a junk command containing a never-ending sequence of characters but never a LF would cause the receiver to allocate memory to store this whole junk command, exhausting memory and crashing the application with an OutOfMemoryError. Users are recommended to upgrade to version 2.20.0 or 3.0.0-M6, which fix this issue by enforcing an upper limit on the length of SCP protocol lines.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.5",
"pubDate": "2026-09-30T10:17:17.740Z",
"pubdate": "2026-09-30T10:17:17.740Z",
"executiveSummary": "A denial-of-service vulnerability involving uncontrolled resource consumption has been identified in the sshd-scp component of Apache MINA SSHD, a Java library utilized for implementing client-side and server-side SSH communications. The vulnerability affects Apache MINA SSHD versions up to 2.19.0, as well as milestone versions 3.0.0-M1 through 3.0.0-M5. The security flaw stems from a lack of input validation and size constraints within the SCP protocol implementation handler, which processes line-oriented, LF-terminated commands.\nBy establishing a connection, a malicious peer can exploit this omission by continuously transmitting a stream of junk characters without ever sending a Line Feed (LF) terminator. Consequently, the receiving application continuously allocates memory buffer space to store the infinite payload, eventually exhausting the available Java Virtual Machine heap memory. This leads to an OutOfMemoryError and crashes the hosting application, resulting in a complete denial of service. Exploitation does not require elevated privileges and can be executed by any peer interacting with the vulnerable service. Organizations utilizing the affected library versions are urged to upgrade to the patched versions, 2.20.0 or 3.0.0-M6, which remediate the issue by enforcing strict upper limits on SCP protocol line lengths.",
"technicalDetails": "The vulnerability exists within the sshd-scp component of the Apache MINA SSHD Java library. This component provides the Java implementation for the Secure Copy Protocol (SCP), which is widely used for secure file transfers over SSH. Structurally, the SCP protocol relies on a line-oriented communication format, where commands are parsed and processed based on Line Feed (LF) character terminators. Under normal operating conditions, the receiving server or client buffers incoming bytes until an LF character is encountered, signifying the end of a discrete protocol command line.\nHowever, the protocol handler in vulnerable versions of sshd-scp (specifically versions up to 2.19.0 and 3.0.0-M1 through 3.0.0-M5) fails to impose any upper bound or maximum length restriction on these incoming SCP protocol lines. This architectural oversight in input handling enables a straightforward resource exhaustion attack.\nTo execute the attack, a malicious network peer establishes an SSH connection and initiates an SCP transaction with the target system running the vulnerable library. Rather than sending valid, terminated SCP commands, the attacker transmits a continuous, uninterrupted stream of junk characters. Because the stream lacks the expected Line Feed (LF) delimiter, the sshd-scp protocol handler continues to read and buffer the incoming data stream indefinitely.\nThe receiving application allocates heap memory dynamically to store the accumulating payload, expecting an LF terminator that never arrives. As the malicious peer continues to feed arbitrary characters, the memory footprint of the socket buffer grows linearly. Eventually, this uncontrolled allocation consumes all available heap memory allocated to the Java Virtual Machine (JVM). The execution of this attack flow leads directly to a Java Virtual Machine (JVM) OutOfMemoryError (OOM), which destabilizes and terminates the hosting application process.\nBecause the attack terminates the application execution, it constitutes a complete Denial of Service (DoS). Network exposure is direct, as the vulnerability is triggerable remotely via the exposed SSH/SCP port. No administrative privileges are required to initiate the connection and send the malformed, non-terminated stream. The vulnerability is resolved in versions 2.20.0 and 3.0.0-M6. In these patched releases, the developers introduced input validation controls that actively enforce a strict, configurable upper limit on the maximum length of SCP protocol lines. If an incoming command exceeds this threshold without an LF terminator, the connection is terminated and resource allocation is safely capped, preventing memory exhaustion."
}