OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-94002

HIGH · CVSS 7.5 EPSS 0.43%

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

The Apache MINA SSHD library's SFTP client is vulnerable to memory exhaustion due to improper handling of unsolicited replies from servers, which can lead to significant resource depletion. This issue affects versions 0.9.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5, making it critical for organizations using these versions to prioritize upgrading to 2.20.0 or 3.0.0-M6 to mitigate potential denial-of-service attacks. Users of the affected SFTP client should address this vulnerability promptly to ensure system stability and security.

CVE
CVE-2026-94002
Severity
HIGH
CVSS
7.5
EPSS
0.43%
Apache Java

Original NVD Description

Possible memory exhaustion in SFTP clients (DefaultSftpClient) in component sshd-sftp in Apache MINA SSHD versions 0.9.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5. Apache MINA SSHD is a Java library for client-side and server-side SSH. The sshd-sftp component provides support for SFTP. The SFTP client implementation, when receiving a reply, did not check that this reply corresponded to a request sent earlier. Unsolicited replies would be stored but never consumed. A malicious server could keep sending unsolicited replies until available memory in the client was exhausted. Users are recommended to upgrade to version 2.20.0 or 3.0.0-M6, which fix this issue.