CVE-2026-94029 Overview
CVE-2026-94029 is a server-side memory exhaustion vulnerability in Apache MINA SSHD, a Java library that provides client-side and server-side SSH support. The flaw resides in the sshd-sftp component, specifically in the SFTP v6 check-file-name and check-file-handle extension handlers. Authenticated clients can request hash computations over very large files using a minimal block size, forcing the server to accumulate the entire reply message in memory. The condition maps to CWE-770 (Allocation of Resources Without Limits or Throttling). Affected releases include Apache MINA SSHD 1.0.0 through 2.19.0 and 3.0.0-M1 through 3.0.0-M5.
Critical Impact
An authenticated SFTP client can crash the server by requesting a hash computation over a large or sparse file with a 256-byte block size, exhausting server-side memory.
Affected Products
- Apache MINA SSHD 1.0.0 through 2.19.0
- Apache MINA SSHD 3.0.0-M1 through 3.0.0-M5
- Applications embedding the sshd-sftp component with SFTP v6 extensions enabled
Discovery Timeline
- 2026-09-30 - CVE-2026-94029 published to NVD
- 2026-09-30 - Last updated in NVD database
Technical Details for CVE-2026-94029
Vulnerability Analysis
The SFTP v6 protocol defines the check-file-name and check-file-handle extensions, which allow a client to request cryptographic hashes over a file in fixed-size blocks. Apache MINA SSHD implements these extensions in its sshd-sftp module. The server computes one hash per block and returns the concatenation of all hashes in a single SFTP reply.
When a client selects a block size of 256 bytes (the minimum permitted) against a large file, the server must generate file_size / 256 hash values. Each hash is appended to an in-memory buffer holding the reply. Because the implementation did not enforce an upper bound on the reply size, the buffer grew unbounded and consumed all available Java heap memory. Sparse files amplify the effect, since a file with a nominal size of tens of gigabytes may occupy little disk yet still trigger the same hash count.
The result is a denial-of-service condition: the JVM eventually throws OutOfMemoryError, and the SSHD server process becomes unresponsive or terminates, disrupting all connected SSH and SFTP sessions.
Root Cause
The root cause is missing input validation and resource throttling in the SFTP v6 extension handler. The server accepted arbitrary block-size and file-size combinations without capping the resulting reply length. Most SFTP implementations, including OpenSSH, enforce a general SFTP message size limit of roughly 256 kB; that safeguard was absent for this code path in Apache MINA SSHD.
Attack Vector
Exploitation requires network access to the SSH service and valid SFTP credentials (PR:L). The attacker authenticates, opens an SFTP v6 session, and issues a check-file-name or check-file-handle request against a large or sparse file using block-size=256. No user interaction is required, and a single request is sufficient to trigger memory exhaustion on a vulnerable server.
No public proof-of-concept code is available. The vulnerability is described in the Apache mailing list thread and the corresponding Openwall OSS-Security discussion.
Detection Methods for CVE-2026-94029
Indicators of Compromise
- SSHD server logs showing java.lang.OutOfMemoryError or GC overhead limit exceeded errors correlated with active SFTP sessions.
- SFTP session traces containing check-file-name or check-file-handle extension requests with a block-size value of 256 or other small values.
- Sudden termination or unresponsiveness of the Apache MINA SSHD JVM following an authenticated SFTP session.
Detection Strategies
- Enable SFTP protocol logging on the SSHD server and alert on invocations of SFTP v6 hash extensions against files larger than a defined threshold.
- Correlate JVM heap-usage spikes with active SFTP client identities to identify the source of the request.
- Track the version string reported by the deployed Apache MINA SSHD library and flag any instance in the vulnerable range.
Monitoring Recommendations
- Instrument the JVM with heap and GC metrics and alert on sustained heap growth in the SSHD process.
- Monitor SFTP session duration and byte-count anomalies; hash-extension abuse typically produces long-lived sessions with disproportionate reply sizes.
- Aggregate SSH authentication events with subsequent process crashes in a central SIEM to build a repeatable detection rule.
How to Mitigate CVE-2026-94029
Immediate Actions Required
- Upgrade Apache MINA SSHD to version 2.20.0 or 3.0.0-M6, which enforce a maximum reply size for SFTP v6 hash extensions.
- Inventory all applications and appliances that embed the sshd-sftp component and prioritize internet-exposed servers.
- Restrict SFTP account privileges and rotate any credentials suspected of misuse.
Patch Information
Apache MINA SSHD 2.20.0 and 3.0.0-M6 fix the issue by imposing an upper bound on the size of the SFTP reply generated by the check-file-name and check-file-handle extensions. This aligns Apache MINA SSHD with the general SFTP message size limit of approximately 256 kB used by OpenSSH and other implementations. Release details are available in the Apache mailing list thread.
Workarounds
- Disable the SFTP v6 check-file-name and check-file-handle extensions in the SSHD server configuration if the deployment does not require them.
- Limit SFTP access to trusted, authenticated users and enforce network-level access controls in front of the SSH service.
- Apply per-user file-size or session resource quotas on the underlying filesystem to reduce the impact of unbounded hash computations.
# Configuration example: update Apache MINA SSHD dependency to a fixed version
# Maven
# <dependency>
# <groupId>org.apache.sshd</groupId>
# <artifactId>sshd-sftp</artifactId>
# <version>2.20.0</version>
# </dependency>
# Gradle
# implementation 'org.apache.sshd:sshd-sftp:2.20.0'
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
