Sceawere
Vulnerability Detail
CVE-2026-94002UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Apache MINA SSHD Memory Exhaustion
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 2h ago
- Vendor
- Apache Software Foundation
- Product
- Apache MINA SSHD
- Attack Type
- CWE-770 Allocation of resources without limits or throttling
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Possible memory exhaustion in SFTP clients (DefaultSftpClient) in component sshd-sftp in Apache MINA SSHD versions 0.9.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5. Apache MINA SSHD is a Java library for client-side and server-side SSH. The sshd-sftp component provides support for SFTP. The SFTP client implementation, when receiving a reply, did not check that this reply corresponded to a request sent earlier. Unsolicited replies would be stored but never consumed. A malicious server could keep sending unsolicited replies until available memory in the client was exhausted. Users are recommended to upgrade to version 2.20.0 or 3.0.0-M6, which fix this issue.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-09-30T10:17:17.877Z",
"pubdate": "2026-09-30T10:17:17.877Z",
"executiveSummary": "The vulnerability involves an improper input validation flaw within the sshd-sftp component of Apache MINA SSHD, leading to a memory exhaustion condition.\nThe issue is classified as a resource exhaustion vulnerability where an attacker-controlled server can force the client to store unsolicited data indefinitely.\nThis affects Apache MINA SSHD versions 0.9.0 through 2.19.0 and 3.0.0-M1 through 3.0.0-M5.\nSuccessful exploitation allows a malicious SSH server to consume the client's heap memory, resulting in a Denial of Service (DoS) state.\nThe vulnerability does not require complex authentication bypasses; it is triggered during the standard exchange of SFTP packets.\nThe primary risk is the destabilization or crash of Java-based applications utilizing this library, which could disrupt downstream business processes.\nThe vulnerability stems from the client's failure to correlate received SFTP responses with pending requests, resulting in the retention of unauthorized state.",
"technicalDetails": "The root cause of the vulnerability resides in the DefaultSftpClient implementation within the sshd-sftp module. The client-side logic lacks a strict validation mechanism to verify that incoming SFTP response packets correspond to valid, previously initiated requests tracked by the client state machine.\nWhen the DefaultSftpClient receives an SFTP packet, it fails to perform a request-response correlation check. Consequently, unsolicited SFTP replies—packets sent by the server without a preceding request from the client—are accepted by the client’s internal processing logic.\nThese unsolicited replies are subsequently placed into internal memory buffers for processing. Because these packets never correspond to a legitimate pending request, the associated client-side logic never triggers a consumption or clearing process for these entries. As a result, the objects remain in memory indefinitely, accumulating over the lifecycle of the connection.\nThe attack flow proceeds as follows: 1) A client initiates a connection to a malicious SSH server. 2) The server begins streaming arbitrary or unsolicited SFTP response packets (such as SSH_FXP_STATUS or SSH_FXP_DATA) to the client at a high rate. 3) The DefaultSftpClient receives these packets and, due to the lack of validation, stores them in an internal collection. 4) As the attacker continues to send these packets, the client's heap memory usage grows linearly. 5) Once the JVM's available heap memory is exhausted, the application will experience an OutOfMemoryError, leading to a service crash or significant performance degradation.\nThis vulnerability is particularly dangerous because it requires no specific user interaction once the connection is established. A malicious server can weaponize the SFTP protocol state machine to perform this resource exhaustion attack against any client connecting to it, provided the client utilizes the affected DefaultSftpClient implementation.\nThe vulnerability exists in Apache MINA SSHD versions 0.9.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5. The exploit is triggered at the network layer during the SFTP session phase, requiring the client to have an active connection to an attacker-controlled endpoint. No administrative or elevated privileges are required on the client side to facilitate this memory corruption, as the vulnerability is inherent to the library's packet processing logic."
}