CVE-2026-94029: Apache MINA SSHD: Memory exhaustion in SFTP v6 check-file-name/check-file-handle extension

Published Sep 29, 2026
·
Updated

Server-side memory exhaustion in Apache MINA SSHD 1.0.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5, component sshd-sftp, in the SFTP v6 check-file-name/check-file-handle extension. Apache MINA SSHD is a Java library for client-side and server-side SSH.

Using a very small "block size" (for instance 256, which is the minimum) on a huge file generates many (file size / block size) hashes. The resulting SFTP reply message was accumulated fully in memory server-side, which could, with a suitably large (possibly sparse) file exhaust the server-side memory, taking down the server.

Users are recommended to upgrade to version 2.20.0 or 3.0.0-M6, which fix this issue by imposing a maximum limit on the size of the reply. Many SFTP implementations have a general limit on the size of SFTP messages anyway; typically 256kB as in OpenSSH or also in Apache MINA SSHD.

Affected Software

1 affected component
Apache MINA SSHD>=1.0.0<=2.19.0, >=3.0.0-M1<=3.0.0-M5

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 2.20.0
  2. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 3.0.0-M6

Event History

Sep 30, 2026
CVE Published
via MITRE·09:35 AM
Data Sourced
via MITRE·09:35 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:17 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to this issue?

Servers using the sshd-sftp component in Apache MINA SSHD versions 1.0.0 through 2.19.0 or 3.0.0-M1 through 3.0.0-M5 are affected when the SFTP v6 check-file-name or check-file-handle extension is available.

2

What does an attacker need to trigger the memory exhaustion?

The attacker needs SFTP access with the privileges required to invoke the affected extension against a huge, potentially sparse file. A very small block size, such as the minimum value of 256, causes the server to generate a large number of hashes and accumulate the full reply in memory.

3

How can this be remediated?

Upgrade Apache MINA SSHD to version 2.20.0 or 3.0.0-M6. These releases impose a maximum limit on the reply size.

4

Is there a mitigation if an upgrade cannot be applied immediately?

Using an SFTP implementation or configuration that enforces a general SFTP message-size limit can reduce exposure. The provided information notes that a 256 kB limit is typical in OpenSSH and Apache MINA SSHD.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203