Skip to content
Rota Nacional

Cyber ·

CVE-2026-94002: memory risk in Apache MINA SSHD

A September 29, 2026 notice reports memory exhaustion in SFTP clients caused by unsolicited responses and lists affected versions.

A security notice published on September 29, 2026, in the oss-sec feed describes CVE-2026-94002, affecting Apache MINA SSHD, a Java library for SSH on both client and server sides. The supplied content is an automatic translation; the original notice is attributed to Thomas Wolf.

According to the text, unsolicited SFTP responses can exhaust memory in DefaultSftpClient, in the sshd-sftp component, causing high availability impact. The reported score is CVSS 3.1 7.5, with vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H; the notice also describes the severity as moderate.

The listed affected versions are Apache MINA SSHD 0.9.0 up to, but not including, 2.20.0, and 3.0.0-M1 up to, but not including, 3.0.0-M6. Check the original notice in the oss-sec feed and the project's official advisories to validate the details and identify the version relevant to your environment. Do not assume the translation contains the full text.

If you use AI to study the notice or analyze related code, remove credentials, personal data, and unnecessary internal details. Share only sanitized excerpts and follow your organization's policy.

Get new articles

Privacy, AI engineering and security in your inbox.

Rota Nacional

Bring privacy into your workflow.

30 days, no card, with a starting quota. After that, Pix credit from R$ 5,00.

Try free