Uncontrolled resource consumption in component ssd-scp in Apache MINA SSHD versions up to 2.19.0 or 3.0.0-M1 to 3.0.0-M5. (CVE-2026-93996)
Uncontrolled resource consumption in component ssd-scp in Apache MINA SSHD versions up to 2.19.0 or 3.0.0-M1 to 3.0.0-M5. Apache MINA SSHD is a Java library for client-side and server-side SSH. Component sshd-scp of Apache MINA SSHD provides a Java implementation of SCP. The SCP command protocol is line-oriented with LF-terminated lines. The protocol handler in sshd-scp did not impose any limit on the length of such protocol lines. A malicious peer just sending a junk command containing a never-ending sequence of characters but never a LF would cause the receiver to allocate memory to store this whole junk command, exhausting memory and crashing the application with an OutOfMemoryError. Users are recommended to upgrade to version 2.20.0 or 3.0.0-M6, which fix this issue by enforcing an upper limit on the length of SCP protocol lines.
AI Analysis
Technical Summary
The sshd-scp component of Apache MINA SSHD, which implements the SCP protocol, did not limit the length of LF-terminated protocol lines. A malicious actor can exploit this by sending a continuous stream of characters without a line feed, causing the receiver to allocate memory indefinitely. This leads to uncontrolled resource consumption and an application crash due to OutOfMemoryError. The vulnerability affects versions up to 2.19.0 and 3.0.0-M1 through 3.0.0-M5. The fix, introduced in versions 2.20.0 and 3.0.0-M6, enforces an upper limit on SCP protocol line length to prevent this condition.
Potential Impact
Exploitation of this vulnerability results in denial of service by exhausting memory resources and crashing the affected application. There is no impact on confidentiality or integrity reported. The CVSS v3.1 score is 6.5 (medium severity) with an attack vector of network, low attack complexity, requiring low privileges, no user interaction, and impacting availability only.
Mitigation Recommendations
Users should upgrade Apache MINA SSHD to version 2.20.0 or 3.0.0-M6 or later, where this vulnerability is fixed by enforcing limits on SCP protocol line length. No other mitigation or temporary workaround is indicated.
Uncontrolled resource consumption in component ssd-scp in Apache MINA SSHD versions up to 2.19.0 or 3.0.0-M1 to 3.0.0-M5. (CVE-2026-93996)
Description
Uncontrolled resource consumption in component ssd-scp in Apache MINA SSHD versions up to 2.19.0 or 3.0.0-M1 to 3.0.0-M5. Apache MINA SSHD is a Java library for client-side and server-side SSH. Component sshd-scp of Apache MINA SSHD provides a Java implementation of SCP. The SCP command protocol is line-oriented with LF-terminated lines. The protocol handler in sshd-scp did not impose any limit on the length of such protocol lines. A malicious peer just sending a junk command containing a never-ending sequence of characters but never a LF would cause the receiver to allocate memory to store this whole junk command, exhausting memory and crashing the application with an OutOfMemoryError. Users are recommended to upgrade to version 2.20.0 or 3.0.0-M6, which fix this issue by enforcing an upper limit on the length of SCP protocol lines.
CVSS v3.1
Score 6.5medium
Affected software
pkg:maven/org.apache.sshd/sshd-scpRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The sshd-scp component of Apache MINA SSHD, which implements the SCP protocol, did not limit the length of LF-terminated protocol lines. A malicious actor can exploit this by sending a continuous stream of characters without a line feed, causing the receiver to allocate memory indefinitely. This leads to uncontrolled resource consumption and an application crash due to OutOfMemoryError. The vulnerability affects versions up to 2.19.0 and 3.0.0-M1 through 3.0.0-M5. The fix, introduced in versions 2.20.0 and 3.0.0-M6, enforces an upper limit on SCP protocol line length to prevent this condition.
Potential Impact
Exploitation of this vulnerability results in denial of service by exhausting memory resources and crashing the affected application. There is no impact on confidentiality or integrity reported. The CVSS v3.1 score is 6.5 (medium severity) with an attack vector of network, low attack complexity, requiring low privileges, no user interaction, and impacting availability only.
Mitigation Recommendations
Users should upgrade Apache MINA SSHD to version 2.20.0 or 3.0.0-M6 or later, where this vulnerability is fixed by enforcing limits on SCP protocol line length. No other mitigation or temporary workaround is indicated.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-6wm4-w8x6-4vvr
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-93996"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6abd30782a4e24523d33ff99
Added to database: 09/30/2026, 15:53:28 UTC
Last enriched: 09/30/2026, 15:55:59 UTC
Last updated: 10/01/2026, 05:08:55 UTC
Views: 10
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.