CVE-2026-94002: CWE-770 Allocation of resources without limits or throttling in Apache Software Foundation Apache MINA SSHD
CVE-2026-94002 is a high-severity vulnerability in Apache MINA SSHD's SFTP client component affecting versions from 0.9.0 up to but not including 2.20.0, and from 3.0.0-M1 up to but not including 3.0.0-M6. The flaw allows a malicious SFTP server to send unsolicited replies that the client stores without consumption, leading to potential memory exhaustion. This can cause denial of service conditions in the client application. The issue is fixed in versions 2.20.0 and 3.0.0-M6.
AI Analysis
Technical Summary
Apache MINA SSHD is a Java library providing SSH client and server functionality, including SFTP support. The vulnerability lies in the SFTP client (DefaultSftpClient) implementation, which does not verify that received replies correspond to previously sent requests. As a result, a malicious server can send unsolicited replies that accumulate in client memory without being processed or cleared, eventually exhausting available memory. This resource exhaustion can disrupt client operations. The vulnerability affects versions >=0.9.0 <2.20.0 and >=3.0.0-M1 <3.0.0-M6. Upgrading to 2.20.0 or 3.0.0-M6 mitigates the issue.
Potential Impact
An attacker controlling an SFTP server can cause a client using vulnerable versions of Apache MINA SSHD to exhaust its memory by sending unsolicited replies. This leads to denial of service on the client side due to memory exhaustion. There is no impact on confidentiality or integrity reported, only availability is affected.
Mitigation Recommendations
Users should upgrade Apache MINA SSHD to version 2.20.0 or 3.0.0-M6 or later, where this issue is fixed. No other mitigation or temporary workaround is indicated.
CVE-2026-94002: CWE-770 Allocation of resources without limits or throttling in Apache Software Foundation Apache MINA SSHD
Description
CVE-2026-94002 is a high-severity vulnerability in Apache MINA SSHD's SFTP client component affecting versions from 0.9.0 up to but not including 2.20.0, and from 3.0.0-M1 up to but not including 3.0.0-M6. The flaw allows a malicious SFTP server to send unsolicited replies that the client stores without consumption, leading to potential memory exhaustion. This can cause denial of service conditions in the client application. The issue is fixed in versions 2.20.0 and 3.0.0-M6.
CVSS v3.1
Score 7.5high
Affected software
Apache Software Foundation
Apache MINA SSHD
pkg:maven/Apache Software Foundation/org.apache.sshd:sshd-sftpRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Apache MINA SSHD is a Java library providing SSH client and server functionality, including SFTP support. The vulnerability lies in the SFTP client (DefaultSftpClient) implementation, which does not verify that received replies correspond to previously sent requests. As a result, a malicious server can send unsolicited replies that accumulate in client memory without being processed or cleared, eventually exhausting available memory. This resource exhaustion can disrupt client operations. The vulnerability affects versions >=0.9.0 <2.20.0 and >=3.0.0-M1 <3.0.0-M6. Upgrading to 2.20.0 or 3.0.0-M6 mitigates the issue.
Potential Impact
An attacker controlling an SFTP server can cause a client using vulnerable versions of Apache MINA SSHD to exhaust its memory by sending unsolicited replies. This leads to denial of service on the client side due to memory exhaustion. There is no impact on confidentiality or integrity reported, only availability is affected.
Mitigation Recommendations
Users should upgrade Apache MINA SSHD to version 2.20.0 or 3.0.0-M6 or later, where this issue is fixed. No other mitigation or temporary workaround is indicated.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- apache
- Date Reserved
- 2026-09-19T14:20:51.289Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6abce0dc0df196e1a9de7076
Added to database: 09/30/2026, 10:13:48 UTC
Last enriched: 09/30/2026, 10:27:11 UTC
Last updated: 09/30/2026, 10:44:21 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.