CVE-2026-77185
- EPSS 0.51%
- Veröffentlicht 30.09.2026 09:47:03
- Zuletzt bearbeitet 30.09.2026 17:16:49
Authentication bypass in sshd-core in Apache MINA SSHD versions 2.0.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5 for a certain (presumed rare) way to implement an SSH server. Apache MINA SSHD is a Java library for client- and server-side SSH. In the serv...
CVE-2026-93994
- EPSS 0.48%
- Veröffentlicht 30.09.2026 09:45:32
- Zuletzt bearbeitet 30.09.2026 16:13:13
Apache MINA SSHD is a Java library for client-side and server-side SSH. SSH servers can be configured to require multi-authentication schemes, for instance two different public keys, not just one. In OpenSSH, this would be done by setting in sshd_con...
CVE-2026-94053
- EPSS 0.55%
- Veröffentlicht 30.09.2026 09:43:47
- Zuletzt bearbeitet 30.09.2026 16:13:13
Authentication bypass via LDAP injection in component sshd-ldap in Apache MINA SSHD versions 1.2.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5. Apache MINA SSHD is a Java library for client-side and server-side SSH. The optional sshd-ldap component provi...
CVE-2026-93995
- EPSS 0.27%
- Veröffentlicht 30.09.2026 09:38:47
- Zuletzt bearbeitet 30.09.2026 16:13:13
Improper input validation in sshd-git in Apache MINA SSHD, versions up to 2.19.0 and 3.0.0-M1 to 3.0.0-M5. Apache MINA SSHD is a Java library for client-side and server-side SSH. Component org.apache.sshd:sshd-git provides though class GitPgmCom...
CVE-2026-93996
- EPSS 0.44%
- Veröffentlicht 30.09.2026 09:37:42
- Zuletzt bearbeitet 30.09.2026 16:13:13
Uncontrolled resource consumption in component ssd-scp in Apache MINA SSHD versions up to 2.19.0 or 3.0.0-M1 to 3.0.0-M5. Apache MINA SSHD is a Java library for client-side and server-side SSH. Component sshd-scp of Apache MINA SSHD provides a Ja...
CVE-2026-94002
- EPSS 0.43%
- Veröffentlicht 30.09.2026 09:37:01
- Zuletzt bearbeitet 30.09.2026 16:13:13
Possible memory exhaustion in SFTP clients (DefaultSftpClient) in component sshd-sftp in Apache MINA SSHD versions 0.9.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5. Apache MINA SSHD is a Java library for client-side and server-side SSH. The sshd-sftp co...
CVE-2026-94029
- EPSS 0.38%
- Veröffentlicht 30.09.2026 09:35:51
- Zuletzt bearbeitet 30.09.2026 20:17:37
Server-side memory exhaustion in Apache MINA SSHD 1.0.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5, component sshd-sftp, in the SFTP v6 check-file-name/check-file-handle extension. Apache MINA SSHD is a Java library for client-side and server-side SSH. U...
CVE-2026-94052
- EPSS 0.55%
- Veröffentlicht 30.09.2026 09:34:43
- Zuletzt bearbeitet 30.09.2026 16:13:13
A missing check in LdapPasswordAuthenticator in component sshd-ldap in Apache MINA SSHD versions 1.2.0 to 2.19.0 or 3.0.0-M1 to 3.0.0-M5 bypassed authentication checks. Apache MINA SSHD is a Java library for client-side and server-side SSH. The o...
CVE-2026-56623
- EPSS 0.59%
- Veröffentlicht 20.07.2026 20:29:08
- Zuletzt bearbeitet 27.07.2026 13:50:42
Path traversal on Windows in Apache MINA SSHD component sshd-git. Apache MINA SSHD is a Java library for client-side and server-side SSH. A git server implemented with Apache MINA SSHD component sshd-git and running on Windows could allow an auth...
CVE-2026-56624
- EPSS 0.18%
- Veröffentlicht 20.07.2026 20:28:26
- Zuletzt bearbeitet 27.07.2026 13:49:18
Improper certificate validation in Apache MINA SSHD (server-side). Apache MINA SSHD is a Java library for client-side and server-side SSH. Server-side OpenSSH user certificate validation during user authentication in an Apache MINA SSHD server di...