A notice published on September 29, 2026 reports inadequate validation in sshd-git that may let a JGit archive operation write a file to the server. It rates the issue moderate, with a CVSS 3.1 score of 6.5.
A translated notice from the oss-sec feed, published by Thomas Wolf on September 29, 2026, describes CVE-2026-93995 in Apache MINA SSHD, a Java library for client- and server-side SSH. According to the text, inadequate input validation in the sshd-git component may allow a JGit archive operation, such as “archive -o=file.zip”, to write a file to the server. The stated rating is moderate: CVSS 3.1 score 6.5, with vector AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N.
The notice lists versions before 2.20.0 and, in the 3.0 line, versions from 3.0.0-M1 to before 3.0.0-M6 as affected. The available excerpt ends partway through the technical description; it does not provide further conditions or remediation steps. To confirm the scope and guide a response, consult the original oss-sec notice and the project's security information, and check the version in use. If using AI to study or apply the material, avoid submitting credentials, personal data, or internal environment details unless necessary; follow your organization's policy.