CVE-2026-94002 Overview
CVE-2026-94002 is a memory exhaustion vulnerability in the DefaultSftpClient component of Apache MINA SSHD. The flaw affects the sshd-sftp module across versions 0.9.0 through 2.19.0, and 3.0.0-M1 through 3.0.0-M5. Apache MINA SSHD is a Java library providing client-side and server-side Secure Shell (SSH) functionality.
The SFTP client fails to validate that incoming replies correspond to outstanding client requests. A malicious server can push unsolicited replies that the client stores indefinitely, exhausting available heap memory. The Apache MINA project has released fixed versions 2.20.0 and 3.0.0-M6.
Critical Impact
A hostile SFTP server can crash any Java application using the vulnerable MINA SSHD client by exhausting client-side memory with unsolicited protocol replies.
Affected Products
- Apache MINA SSHD versions 0.9.0 through 2.19.0
- Apache MINA SSHD versions 3.0.0-M1 through 3.0.0-M5
- The sshd-sftp component (SFTP client DefaultSftpClient)
Discovery Timeline
- 2026-09-30 - CVE-2026-94002 published to the National Vulnerability Database (NVD)
- 2026-09-30 - Last updated in NVD database
Technical Details for CVE-2026-94002
Vulnerability Analysis
The vulnerability resides in the SFTP client reply-handling logic within DefaultSftpClient. When the client receives a response packet from an SFTP server, it does not verify that the reply corresponds to a previously issued request identifier. Instead, the client stores the reply in an internal collection awaiting consumption.
Because unsolicited replies match no pending request, they are never removed. A malicious or compromised server can transmit an unbounded stream of these unsolicited response packets. Each packet consumes client heap memory until the Java Virtual Machine (JVM) throws OutOfMemoryError or becomes unresponsive.
This behavior maps to CWE-770: Allocation of Resources Without Limits or Throttling. The impact is confined to availability. The vulnerability does not permit code execution, credential disclosure, or file tampering.
Root Cause
The SFTP protocol assigns each request a unique request ID that the server echoes in the matching reply. The vulnerable DefaultSftpClient implementation queues all received replies without correlating them against outstanding request IDs. There is no upper bound on the size of the pending-reply store and no timeout on stored entries.
Attack Vector
An attacker must control an SFTP server that a vulnerable client connects to. This includes malicious servers, compromised legitimate servers, or man-in-the-middle scenarios where an attacker intercepts an SFTP session before authentication completes. Once a connection is established, the attacker streams arbitrary SFTP reply packets with fabricated request IDs. The client absorbs each packet into its reply buffer until the process exhausts its heap.
No authentication or user interaction is required beyond the client initiating the SFTP connection. The attack requires only network-adjacent positioning as an SFTP endpoint.
A proof-of-concept exploit has not been published. See the Apache mailing list thread and the Openwall OSS Security advisory for authoritative technical detail.
Detection Methods for CVE-2026-94002
Indicators of Compromise
- Java processes hosting sshd-sftp clients exhibiting sustained heap growth during or after SFTP sessions.
- java.lang.OutOfMemoryError events in application logs correlated with active SFTP connections.
- Unusually large SFTP response volume from a single server relative to client-issued requests.
Detection Strategies
- Inventory application dependencies for org.apache.sshd:sshd-sftp at versions 0.9.0 through 2.19.0 or 3.0.0-M1 through 3.0.0-M5 using Software Composition Analysis (SCA) tooling.
- Instrument JVM heap metrics on hosts running MINA SSHD SFTP clients and alert on sustained growth without garbage collection recovery.
- Capture network telemetry on port 22 traffic and flag sessions where server-to-client packet counts substantially exceed client-to-server request counts.
Monitoring Recommendations
- Forward JVM metrics and application logs to a centralized analytics platform for correlation across affected services.
- Monitor outbound SFTP connections to untrusted or newly observed servers.
- Track dependency manifests (pom.xml, build.gradle) in continuous integration pipelines to identify vulnerable MINA SSHD versions before deployment.
How to Mitigate CVE-2026-94002
Immediate Actions Required
- Upgrade Apache MINA SSHD to version 2.20.0 or 3.0.0-M6.
- Audit all applications and services embedding sshd-sftp and prioritize those making outbound SFTP connections to third-party servers.
- Restrict SFTP client connections to a known allowlist of trusted server endpoints where feasible.
Patch Information
The Apache MINA project fixed the issue in sshd-sftp versions 2.20.0 and 3.0.0-M6. The patched DefaultSftpClient validates that each incoming reply matches an outstanding request identifier and discards unsolicited responses. Consult the Apache mailing list thread for release details.
Workarounds
- Configure firewall rules or egress proxies to restrict SFTP client connections to trusted server hosts only.
- Enforce JVM heap limits with -Xmx so that a memory-exhaustion attempt fails fast and can be restarted automatically by the process supervisor.
- Isolate SFTP client workloads in dedicated processes or containers so that exhaustion does not affect unrelated services.
# Maven dependency upgrade example
# Replace vulnerable version with the fixed release
mvn versions:use-dep-version \
-Dincludes=org.apache.sshd:sshd-sftp \
-DdepVersion=2.20.0 \
-DforceVersion=true
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
