CVE-2026-94029
Description
A flaw was found in Apache MINA SSHD. When processing SSH File Transfer Protocol (SFTP) check-file extensions, the server accumulates file hash verification responses entirely in memory without enforcing a size limit. An authenticated remote attacker can exploit this vulnerability by requesting file verification with a minimal block size on a large file, leading to memory exhaustion and a Denial of Service (DoS).
Statement
A flaw was found in Apache MINA SSHD's SFTP v6 check-file-name and check-file-handle extension implementation. When an authenticated SFTP user specifies a very small block size (for instance 256 bytes, which is the minimum) on a large file, the server generates many hashes equal to (file size / block size). The resulting SFTP reply message is accumulated fully in memory server-side without limits or throttling. An attacker with valid SFTP credentials can exploit this by using a suitably large (possibly sparse) file to exhaust the server's memory, causing a denial of service and taking down the SFTP server.
Red Hat ships vulnerable versions of Apache MINA SSHD in JBoss Fuse 7 (Extended Lifecycle Support), Konflux Pipeline, Red Hat build of Apache Camel (Quarkus and Spring Boot variants), and Red Hat Integration Service Registry. Fixed version 2.20.0 is available, which addresses this issue by imposing a maximum limit on the size of the reply message.
Mitigation
There is no mitigation available for this issue. Apply updates as they become available from Red Hat product teams. As a temporary workaround, consider implementing resource limits at the OS level (ulimit, cgroups) to prevent a single process from exhausting all available memory, or restrict SFTP access to trusted users only.
Common Vulnerability Scoring System (CVSS) Score Details
Info alert:Important note
CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).
The following CVSS metrics and score provided are preliminary and subject to review.
CVSS v3 Score Breakdown
| Red Hat | NVD | cve.org | |
|---|---|---|---|
| Base Score | 6.5 | N/A | 6.5 |
| Attack Vector | Network | N/A | Network |
| Attack Complexity | Low | N/A | Low |
| Privileges Required | Low | N/A | Low |
| User Interaction | None | N/A | None |
| Scope | Unchanged | N/A | Unchanged |
| Confidentiality | None | N/A | None |
| Integrity Impact | None | N/A | None |
| Availability Impact | High | N/A | High |
Vector
Red Hat: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
cve.org: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Understanding the Weakness (CWE)
Availability
Technical Impact: DoS: Resource Consumption (CPU); DoS: Resource Consumption (Memory); DoS: Resource Consumption (Other)
When allocating resources without limits, an attacker could prevent other systems, applications, or processes from accessing the same type of resource. It can be easy for an attacker to consume many resources by rapidly making many requests or causing larger resources to be used than is needed.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.