Skip to content
Rota Nacional

Cyber ·

CVE-2026-94029 in Apache MINA SSHD: memory exhaustion risk

A notice published on September 29, 2026 reports a moderate flaw in Apache MINA SSHD's sshd-sftp component. Exploitation requires privileges and may exhaust server memory; the excerpt lists fixed versions starting at 2.20.0 and 3.0.0-M6.

The notice, published on September 29, 2026 and presented as an automatic translation of a post on the oss-sec feed, describes CVE-2026-94029 in Apache MINA SSHD's sshd-sftp component. The flaw is in the SFTP v6 check-file-name/check-file-handle extension and may cause server-side memory exhaustion.

The stated rating is CVSS 3.1 6.5, medium severity. The vector requires network access and low privileges; it indicates no confidentiality or integrity impact, but high availability impact. The notice lists Apache MINA SSHD versions 1.0.0 before 2.20.0 and 3.0.0-M1 before 3.0.0-M6 as affected.

If your team maintains systems that use this library, identify the installed version and compare it with the affected ranges. Plan an upgrade to an unaffected version and validate the change through your deployment process; the supplied excerpt does not detail workarounds or every remediation step.

To verify the details, consult the original notice on the oss-sec feed and the official Apache MINA SSHD project documentation. Compare the CVE identifier, versions, and severity assessment: the available text is an automatic translation and ends mid-sentence. If you use AI to summarize or study the notice, avoid entering credentials, personal data, or unnecessary internal details.

Get new articles

Privacy, AI engineering and security in your inbox.

Rota Nacional

Bring privacy into your workflow.

30 days, no card, with a starting quota. After that, Pix credit from R$ 5,00.

Try free