Apache MINA SSHD

8 known vulnerabilities in Apache MINA SSHD, 3 critical, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-94053 CVSS 9.1 critical Authentication bypass via LDAP injection in component sshd-ldap in Apache MINA SSHD versions 1.2.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5…
  • CVE-2026-94052 CVSS 9.1 critical A missing check in LdapPasswordAuthenticator in component sshd-ldap in Apache MINA SSHD versions 1.2.0 to 2.19.0 or 3.0.0-M1 to 3.0.0-M5…
  • CVE-2026-94029 CVSS 6.5 medium Server-side memory exhaustion in Apache MINA SSHD 1.0.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5, component sshd-sftp, in the SFTP v6…
  • CVE-2026-94002 CVSS 7.5 high Possible memory exhaustion in SFTP clients (DefaultSftpClient) in component sshd-sftp in Apache MINA SSHD versions 0.9.0 to 2.19.0 and…
  • CVE-2026-93996 CVSS 6.5 medium Uncontrolled resource consumption in component ssd-scp in Apache MINA SSHD versions up to 2.19.0 or 3.0.0-M1 to 3.0.0-M5. Apache MINA SSHD…
  • CVE-2026-93995 CVSS 6.5 medium Improper input validation in sshd-git in Apache MINA SSHD, versions up to 2.19.0 and 3.0.0-M1 to 3.0.0-M5. Apache MINA SSHD is a Java…
  • CVE-2026-93994 CVSS 8.1 high Apache MINA SSHD is a Java library for client-side and server-side SSH. SSH servers can be configured to require multi-authentication…
  • CVE-2026-77185 CVSS 9.1 critical Authentication bypass in sshd-core in Apache MINA SSHD versions 2.0.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5 for a certain (presumed rare) way…