CVE-2026-94002: Apache MINA SSHD: Memory exhaustion in SFTP client via unsolicited SFTP replies
Possible memory exhaustion in SFTP clients (DefaultSftpClient) in component sshd-sftp in Apache MINA SSHD versions 0.9.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5.
Apache MINA SSHD is a Java library for client-side and server-side SSH. The sshd-sftp component provides support for SFTP.
The SFTP client implementation, when receiving a reply, did not check that this reply corresponded to a request sent earlier. Unsolicited replies would be stored but never consumed. A malicious server could keep sending unsolicited replies until available memory in the client was exhausted.
Users are recommended to upgrade to version 2.20.0 or 3.0.0-M6, which fix this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache MINA SSHD sshd-sftpto a version that resolves this vulnerability.Fixed in 2.20.0 - Upgrade
Upgrade
Apache MINA SSHD sshd-sftpto a version that resolves this vulnerability.Fixed in 3.0.0-M6
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Applications using the sshd-sftp component's DefaultSftpClient in Apache MINA SSHD versions 0.9.0 through 2.19.0, or 3.0.0-M1 through 3.0.0-M5, are affected. The exposure is on the client side when it connects to a malicious SFTP server.
What does an attacker need to do to exhaust client memory?
An attacker needs to operate or control an SFTP server that the affected client connects to. The server can send unsolicited SFTP replies that do not correspond to earlier client requests, causing them to be retained without being consumed.
Is authentication or user interaction required for exploitation?
No. The supplied vector indicates network exploitation with low attack complexity and no privileges or user interaction required; the relevant condition is that the affected client communicates with a malicious server.
What should be done to remediate the issue?
Upgrade Apache MINA SSHD to version 2.20.0 or 3.0.0-M6. These versions fix the handling of unsolicited SFTP replies.