CVE-2026-58624
- EPSS 0.42%
- Veröffentlicht 20.07.2026 20:27:39
- Zuletzt bearbeitet 27.07.2026 14:25:52
Improper input validation in sshd-git in Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side and server-side SSH. Component org.apache.sshd:sshd-git provides though its GitPgmCommandFactory a way to configure an Apache MINA SSHD ...
CVE-2026-56452
- EPSS 0.57%
- Veröffentlicht 20.07.2026 20:26:28
- Zuletzt bearbeitet 27.07.2026 13:49:31
Path traversal in the sshd-scp component of Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side and server-side SSH. The implementation of receiving files or directories via SCP did not validate filenames in SCP "C" or "D" comman...
CVE-2026-48827
- EPSS 0.53%
- Veröffentlicht 01.06.2026 09:16:20
- Zuletzt bearbeitet 22.07.2026 07:10:00
Path traversal vulnerability in Apache MINA SSHD bundle sshd-git. Lack of path validation in git-upload-pack, git-receive-pack, and other git operations allows users authenticated over SSH access to git repositories outside the configured git server ...
CVE-2024-41909
- EPSS 0.58%
- Veröffentlicht 12.08.2024 16:15:15
- Zuletzt bearbeitet 27.03.2025 16:15:26
Like many other SSH implementations, Apache MINA SSHD suffered from the issue that is more widely known as CVE-2023-48795. An attacker that can intercept traffic between client and server could drop certain packets from the stream, potentially causin...
CVE-2019-6111
- EPSS 58.2%
- Veröffentlicht 31.01.2019 18:29:00
- Zuletzt bearbeitet 18.12.2025 15:15:48
An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses which files/directories are sent to the client. However, the scp client only performs cursory validation of the object name returned...