CVE-2026-94002
Description
A flaw was found in the sshd-sftp component of Apache MINA SSHD. This vulnerability allows a malicious server to cause a Denial of Service (DoS) on the client by exhausting system memory. The SFTP (SSH File Transfer Protocol) client fails to verify whether incoming replies correspond to previously sent requests, indefinitely retaining unrequested replies. A rogue server can exploit this by continuously sending unsolicited messages until all available client memory is consumed.
Statement
A flaw was found in Apache MINA SSHD's SFTP client implementation (DefaultSftpClient). When the client receives an SFTP reply from a server, it does not validate that this reply corresponds to a request sent earlier. A malicious SFTP server can exploit this by continuously sending unsolicited replies that get stored in the client's memory but are never consumed. This allows an attacker who controls or has compromised an SFTP server to exhaust the available memory in any client that connects to it, causing a denial of service and crashing the client application.
Red Hat ships vulnerable versions of Apache MINA SSHD in JBoss Fuse 7 (Extended Lifecycle Support), Konflux Pipeline, Red Hat build of Apache Camel (Quarkus and Spring Boot variants), and Red Hat Integration Service Registry. These products use SFTP client functionality that could connect to malicious or compromised SFTP servers. Fixed version 2.20.0 is available, which addresses this issue by validating that replies correspond to earlier requests.
Mitigation
There is no mitigation available for this issue. Apply updates as they become available from Red Hat product teams. As a temporary workaround, only connect to trusted SFTP servers, implement monitoring to detect abnormal memory consumption in SFTP client processes, and configure resource limits (ulimit, cgroups) to prevent a single process from exhausting all available memory.
Common Vulnerability Scoring System (CVSS) Score Details
Info alert:Important note
CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).
The following CVSS metrics and score provided are preliminary and subject to review.
CVSS v3 Score Breakdown
| Red Hat | NVD | cve.org | |
|---|---|---|---|
| Base Score | 7.5 | N/A | 7.5 |
| Attack Vector | Network | N/A | Network |
| Attack Complexity | Low | N/A | Low |
| Privileges Required | None | N/A | None |
| User Interaction | None | N/A | None |
| Scope | Unchanged | N/A | Unchanged |
| Confidentiality | None | N/A | None |
| Integrity Impact | None | N/A | None |
| Availability Impact | High | N/A | High |
Vector
Red Hat: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
cve.org: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Understanding the Weakness (CWE)
Availability
Technical Impact: DoS: Resource Consumption (CPU); DoS: Resource Consumption (Memory); DoS: Resource Consumption (Other)
When allocating resources without limits, an attacker could prevent other systems, applications, or processes from accessing the same type of resource. It can be easy for an attacker to consume many resources by rapidly making many requests or causing larger resources to be used than is needed.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.