Answer in brief
CVE-2026-94002 records a High severity (CVSS 7.5) vulnerability in Apache MINA SSHD: Memory exhaustion in SFTP client via unsolicited SFTP replies. The current sources do not mark it as known exploited. The current feed maps Apache Software Foundation/org.apache.sshd:sshd-sftp (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 7.5. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Apache Software Foundation/org.apache.sshd:sshd-sftp (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Apache Software Foundation/org.apache.sshd:sshd-sftpgeneric | >=0.9.0 <2.20.0 || >=3.0.0-M1 <3.0.0-M6 | 2.20.0, 3.0.0-M6 |
Published upstream
Sep 30, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 30, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 30, 2026
Possible memory exhaustion in SFTP clients (DefaultSftpClient) in component sshd-sftp in Apache MINA SSHD versions 0.9.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5. Apache MINA SSHD is a Java library for client-side and server-side SSH. The sshd-sftp component provides support for SFTP. The SFTP client implementation, when receiving a reply, did not check that this reply corresponded to a request sent earlier. Unsolicited replies would be stored but never consumed. A malicious server could keep sending unsolicited replies until available memory in the client was exhausted. Users are recommended to upgrade to version 2.20.0 or 3.0.0-M6, which fix this issue.
Quoted source text, attributed separately from HOL analysis.