CVE-2026-93996: Apache MINA SSHD: Memory exhaustion DoS via unbounded SCP command line read

Published Sep 29, 2026
·
Updated

Uncontrolled resource consumption in component ssd-scp in Apache MINA SSHD versions up to 2.19.0 or 3.0.0-M1 to 3.0.0-M5. Apache MINA SSHD is a Java library for client-side and server-side SSH.

Component sshd-scp of Apache MINA SSHD provides a Java implementation of SCP. The SCP command protocol is line-oriented with LF-terminated lines. The protocol handler in sshd-scp did not impose any limit on the length of such protocol lines. A malicious peer just sending a junk command containing a never-ending sequence of characters but never a LF would cause the receiver to allocate memory to store this whole junk command, exhausting memory and crashing the application with an OutOfMemoryError.

Users are recommended to upgrade to version 2.20.0 or 3.0.0-M6, which fix this issue by enforcing an upper limit on the length of SCP protocol lines.

Affected Software

1 affected component
Apache MINA SSHD<=2.19.0, >=3.0.0-M1<=3.0.0-M5

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Apache MINA SSHD sshd-scp to a version that resolves this vulnerability.

    Fixed in 2.20.0
  2. Upgrade

    Upgrade Apache MINA SSHD sshd-scp to a version that resolves this vulnerability.

    Fixed in 3.0.0-M6

Event History

Sep 30, 2026
CVE Published
via MITRE·09:37 AM
Data Sourced
via MITRE·09:37 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:17 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to this issue?

Deployments using the sshd-scp component of Apache MINA SSHD are affected if they run versions up to 2.19.0 or versions 3.0.0-M1 through 3.0.0-M5. The issue applies to both client-side and server-side SSH uses of the library when handling SCP protocol input from a peer.

2

What must an attacker be able to do to trigger the denial of service?

An attacker needs to act as, or control, an SCP protocol peer that the affected application reads from. They can send a command line that never includes the required LF terminator, causing the receiver to continue allocating memory until an OutOfMemoryError crashes the application.

3

Is authentication required for exploitation?

Yes. The supplied severity vector specifies low privileges required (PR:L), meaning the attacker needs some authenticated or otherwise authorized ability to interact with the affected SCP endpoint or client.

4

What is the remediation?

Upgrade Apache MINA SSHD to version 2.20.0 or 3.0.0-M6. These releases enforce an upper limit on SCP protocol-line length.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203