Vulnerabilidad · Publicado 30/09/2026
Apache MINA SSHD versiones 0.9.0 a 2.19.0 y 3.0.0-M1 a 3.0.0-M5 contienen una vulnerabilidad de agotamiento de memoria en el componente sshd-sftp. El cliente SFTP (DefaultSftpClient) no valida que las respuestas recibidas correspondan a solicitudes legítimas, permitiendo consumo excesivo de recursos. Afecta a aplicaciones Java que utilizan esta biblioteca para transferencia de archivos segura.
Possible memory exhaustion in SFTP clients (DefaultSftpClient) in component sshd-sftp in Apache MINA SSHD versions 0.9.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5. Apache MINA SSHD is a Java library for client-side and server-side SSH. The sshd-sftp component provides support for SFTP. The SFTP client implementation, when receiving a reply, did not check that this reply corresponded to a request sent earlier. Unsolicited replies would be stored but never consumed. A malicious server could keep sending unsolicited replies until available memory in the client was exhausted. Users are recommended to upgrade to version 2.20.0 or 3.0.0-M6, which fix this issue.
Score: 7.5/10 — Severidad: HIGH — Estado NIST: Received
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-770
Publicado en NIST NVD.