CVE-2026-94002

Description

A flaw was found in the sshd-sftp component of Apache MINA SSHD. This vulnerability allows a malicious server to cause a Denial of Service (DoS) on the client by exhausting system memory. The SFTP (SSH File Transfer Protocol) client fails to verify whether incoming replies correspond to previously sent requests, indefinitely retaining unrequested replies. A rogue server can exploit this by continuously sending unsolicited messages until all available client memory is consumed.

Statement

A flaw was found in Apache MINA SSHD's SFTP client implementation (DefaultSftpClient). When the client receives an SFTP reply from a server, it does not validate that this reply corresponds to a request sent earlier. A malicious SFTP server can exploit this by continuously sending unsolicited replies that get stored in the client's memory but are never consumed. This allows an attacker who controls or has compromised an SFTP server to exhaust the available memory in any client that connects to it, causing a denial of service and crashing the client application.

Red Hat ships vulnerable versions of Apache MINA SSHD in JBoss Fuse 7 (Extended Lifecycle Support), Konflux Pipeline, Red Hat build of Apache Camel (Quarkus and Spring Boot variants), and Red Hat Integration Service Registry. These products use SFTP client functionality that could connect to malicious or compromised SFTP servers. Fixed version 2.20.0 is available, which addresses this issue by validating that replies correspond to earlier requests.

Mitigation

There is no mitigation available for this issue. Apply updates as they become available from Red Hat product teams. As a temporary workaround, only connect to trusted SFTP servers, implement monitoring to detect abnormal memory consumption in SFTP client processes, and configure resource limits (ulimit, cgroups) to prevent a single process from exhausting all available memory.

Common Vulnerability Scoring System (CVSS) Score Details

Info alert:Important note

CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).

The following CVSS metrics and score provided are preliminary and subject to review.

CVSS v3 Score Breakdown

Red HatNVDcve.org
Base Score7.5N/A7.5
Attack VectorNetworkN/ANetwork
Attack ComplexityLowN/ALow
Privileges RequiredNoneN/ANone
User InteractionNoneN/ANone
ScopeUnchangedN/AUnchanged
ConfidentialityNoneN/ANone
Integrity ImpactNoneN/ANone
Availability ImpactHighN/AHigh

Vector

Red Hat: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

cve.org: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Understanding the Weakness (CWE)

Availability

Technical Impact: DoS: Resource Consumption (CPU); DoS: Resource Consumption (Memory); DoS: Resource Consumption (Other)

When allocating resources without limits, an attacker could prevent other systems, applications, or processes from accessing the same type of resource. It can be easy for an attacker to consume many resources by rapidly making many requests or causing larger resources to be used than is needed.

Frequently Asked Questions

Want to get errata notifications? Sign up here.