An advisory published on September 29, 2026 reports uncontrolled resource consumption while reading SCP command lines in the sshd-scp component. It rates the issue moderate, with a CVSS 3.1 score of 6.5.
An advisory attributed to Thomas Wolf and published in the oss-sec feed on September 29, 2026 describes CVE-2026-93996 in Apache MINA SSHD, a Java library for client- and server-side SSH. The text says that reading an SCP command line without a limit can cause uncontrolled resource consumption in the sshd-scp component and affect availability. The stated rating is moderate: CVSS 3.1 score 6.5; vector AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H.
The advisory lists versions before 2.20.0 and versions 3.0.0-M1 through 3.0.0-M5 as affected; it also indicates that 3.0.0-M6 is outside that affected range. To confirm the scope, consult the original advisory in the oss-sec feed and check the publication and technical details against Apache MINA SSHD project sources. The available text is an automatic translation and ends incomplete, so it does not support adding remediation instructions. If using AI to analyze logs or apply the material, remove personal data and secrets before submission and follow your organization’s policy.