CVE-2026-93996: Apache MINA SSHD: Memory exhaustion DoS via unbounded SCP command line read
Uncontrolled resource consumption in component ssd-scp in Apache MINA SSHD versions up to 2.19.0 or 3.0.0-M1 to 3.0.0-M5. Apache MINA SSHD is a Java library for client-side and server-side SSH.
Component sshd-scp of Apache MINA SSHD provides a Java implementation of SCP. The SCP command protocol is line-oriented with LF-terminated lines. The protocol handler in sshd-scp did not impose any limit on the length of such protocol lines. A malicious peer just sending a junk command containing a never-ending sequence of characters but never a LF would cause the receiver to allocate memory to store this whole junk command, exhausting memory and crashing the application with an OutOfMemoryError.
Users are recommended to upgrade to version 2.20.0 or 3.0.0-M6, which fix this issue by enforcing an upper limit on the length of SCP protocol lines.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache MINA SSHD sshd-scpto a version that resolves this vulnerability.Fixed in 2.20.0 - Upgrade
Upgrade
Apache MINA SSHD sshd-scpto a version that resolves this vulnerability.Fixed in 3.0.0-M6
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Deployments using the sshd-scp component of Apache MINA SSHD are affected if they run versions up to 2.19.0 or versions 3.0.0-M1 through 3.0.0-M5. The issue applies to both client-side and server-side SSH uses of the library when handling SCP protocol input from a peer.
What must an attacker be able to do to trigger the denial of service?
An attacker needs to act as, or control, an SCP protocol peer that the affected application reads from. They can send a command line that never includes the required LF terminator, causing the receiver to continue allocating memory until an OutOfMemoryError crashes the application.
Is authentication required for exploitation?
Yes. The supplied severity vector specifies low privileges required (PR:L), meaning the attacker needs some authenticated or otherwise authorized ability to interact with the affected SCP endpoint or client.
What is the remediation?
Upgrade Apache MINA SSHD to version 2.20.0 or 3.0.0-M6. These releases enforce an upper limit on SCP protocol-line length.