CVE-2026-77185: Apache MINA SSHD: Asynchronous authentication can bypass signature verification
Authentication bypass in sshd-core in Apache MINA SSHD versions 2.0.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5 for a certain (presumed rare) way to implement an SSH server.
Apache MINA SSHD is a Java library for client- and server-side SSH. In the server part of the library, a mechanism to perform "asynchronous authentication" exists. A server implemented with Apache MINA SSHD must contain explicit code to make use of this feature. The implementation of this feature was flawed and could potentially lead to skipping checking the signature in public-key or hostbased authentication, or returning a wrong result.
Users are recommended to upgrade to Apache MINA SSHD 2.20.0 or 3.0.0-M6, which fix the logic error and which additionally forbid the use of this "asynchronous authentication" mechanism with the public-key or hostbased authentication schemes: if used, the SSH session will be closed and the server will log an entry indicating that asynchronous authentication may be used only with password or keyboard-interactive authentication.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache MINA SSHDto a version that resolves this vulnerability.Fixed in 2.20.0 - Upgrade
Upgrade
Apache MINA SSHDto a version that resolves this vulnerability.Fixed in 3.0.0-M6
Event History
Frequently Asked Questions
Which deployments are affected in practice?
Only Apache MINA SSHD server implementations that explicitly use its asynchronous authentication feature are affected. The issue is described as applying to a presumed rare implementation pattern; ordinary use of the library without explicit asynchronous authentication code is not indicated as affected.
What authentication methods are at risk?
The flawed logic can skip signature verification or return an incorrect result for public-key or hostbased authentication when asynchronous authentication is used. Password and keyboard-interactive authentication are not identified as having this signature-verification issue.
What should teams do if they use asynchronous authentication?
Upgrade to Apache MINA SSHD 2.20.0 or 3.0.0-M6. These versions fix the logic error and reject asynchronous authentication with public-key or hostbased schemes by closing the SSH session and logging an entry.
How can an operator identify potentially affected usage?
Review the SSH server implementation for explicit use of Apache MINA SSHD's asynchronous authentication mechanism, especially alongside public-key or hostbased authentication. After upgrading, attempts to use that combination cause the session to close and generate a log entry stating that asynchronous authentication is permitted only for password or keyboard-interactive authentication.