#1149652 libmina-sshd-java: CVE-2026-77185 CVE-2026-93994 CVE-2026-93995 CVE-2026-93996 CVE-2026-94002 CVE-2026-94029 CVE-2026-94052 CVE-2026-94053

Package:
src:libmina-sshd-java
Source:
src:libmina-sshd-java
Submitter:
Salvatore Bonaccorso
Date:
2026-10-01 21:37:02 UTC
Severity:
normal
Tags:
#1149652#5
Date:
2026-10-01 21:34:57 UTC
From:
To:
Hi,

The following vulnerabilities were published for libmina-sshd-java.

CVE-2026-77185[0]:
| Authentication bypass in sshd-core in Apache MINA SSHD versions
| 2.0.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5 for a certain (presumed
| rare) way to implement an SSH server.     Apache MINA SSHD is a Java
| library for client- and server-side SSH. In the server part of the
| library, a mechanism to perform "asynchronous authentication"
| exists. A server implemented with Apache MINA SSHD must contain
| explicit code to make use of this feature. The implementation of
| this feature was flawed and could potentially lead to skipping
| checking the signature in public-key or hostbased authentication, or
| returning a wrong result.     Users are recommended to upgrade
| to Apache MINA SSHD 2.20.0 or 3.0.0-M6, which fix the logic error
| and which additionally forbid the use of this "asynchronous
| authentication" mechanism with the public-key or hostbased
| authentication schemes: if used, the SSH session will be closed and
| the server will log an entry indicating that asynchronous
| authentication may be used only with password or keyboard-
| interactive authentication.


CVE-2026-93994[1]:
| Apache MINA SSHD is a Java library for client-side and server-side
| SSH. SSH servers can be configured to require multi-authentication
| schemes, for instance two different public keys, not just one. In
| OpenSSH, this would be done by setting in sshd_config
| AuthenticationMethods "publickey,publickey". Apache MINA SSHD
| provides an equivalent configuration mechanism.     In Apache MINA
| SSHD versions up to 2.19.0 and 3.0.0-M1 to 3.0.0-M5 the server code
| in component sshd-core does not enforce that the two public keys
| presented are different. A user can thus successfully authenticate
| with only one of the two key pairs required by presenting this
| single key twice. This is a partial authentication bypass.
| Users are recommended to upgrade to version 2.20.0 or 3.0.0-M6,
| which fix this issue.


CVE-2026-93995[2]:
| Improper input validation in sshd-git in Apache MINA SSHD, versions
| up to 2.19.0 and 3.0.0-M1 to 3.0.0-M5. Apache  MINA SSHD is a Java
| library for client-side and server-side SSH.     Component
| org.apache.sshd:sshd-git provides though class GitPgmCommandFactory
| a way to configure an Apache MINA SSHD server such  that
| authenticated SSH clients can remotely execute git commands via the
| JGit library  on git repositories stored on the server.
| In CVE-2026-58624 this mechanism was restricted to only a few git
| commands, including "git archive" without "--output" or "-o" options
| such that the resulting archive would not be written on the server
| but instead sent back to the client over the SSH connection.     The
| fix done for CVE-2026-58624 was insufficient as it missed removing
| the single-argument "-o=file.zip" version of the command
| parameter from the "archive" command.     Users are recommended to
| upgrade to version 2.20.0 or 3.0.0-M6, which fix this issue.


CVE-2026-93996[3]:
| Uncontrolled resource consumption in component ssd-scp in Apache
| MINA SSHD versions up to 2.19.0 or 3.0.0-M1 to 3.0.0-M5. Apache MINA
| SSHD is a Java library for client-side and server-side SSH.
| Component sshd-scp of Apache MINA SSHD provides a Java
| implementation of SCP. The SCP command protocol is line-oriented
| with LF-terminated lines. The protocol handler in sshd-scp did not
| impose any limit on the length of such protocol lines. A malicious
| peer just sending a junk command containing a never-ending sequence
| of characters but never a LF would cause the receiver to allocate
| memory to store this whole junk command, exhausting memory and
| crashing the application with an OutOfMemoryError.     Users are
| recommended to upgrade to version 2.20.0 or 3.0.0-M6, which fix this
| issue by enforcing an upper limit on the length of SCP protocol
| lines.


CVE-2026-94002[4]:
| Possible memory exhaustion in SFTP clients (DefaultSftpClient) in
| component sshd-sftp in Apache MINA SSHD versions 0.9.0 to 2.19.0 and
| 3.0.0-M1 to 3.0.0-M5.     Apache  MINA SSHD is a Java library for
| client-side and server-side SSH. The sshd-sftp component provides
| support for SFTP.     The SFTP client implementation, when receiving
| a reply, did not check that this reply corresponded to a request
| sent earlier. Unsolicited replies would be stored but never
| consumed. A malicious server could keep sending unsolicited replies
| until available memory in the client was exhausted.     Users are
| recommended to upgrade to version 2.20.0 or 3.0.0-M6, which fix this
| issue.


CVE-2026-94029[5]:
| Server-side memory exhaustion in Apache MINA SSHD 1.0.0 to 2.19.0
| and 3.0.0-M1 to 3.0.0-M5, component sshd-sftp, in the SFTP v6 check-
| file-name/check-file-handle extension. Apache MINA SSHD is a Java
| library for client-side and server-side SSH.     Using a very small
| "block size" (for instance 256, which is the minimum) on a huge file
| generates many (file size / block size) hashes. The resulting SFTP
| reply message was accumulated fully in memory server-side, which
| could, with a suitably large (possibly sparse) file exhaust the
| server-side memory, taking down the server.     Users are
| recommended to upgrade to version 2.20.0 or 3.0.0-M6, which fix this
| issue by imposing a maximum limit on the size of the reply. Many
| SFTP implementations have a general limit on the size of SFTP
| messages anyway; typically 256kB as in OpenSSH or also in Apache
| MINA SSHD.


CVE-2026-94052[6]:
| A missing check in LdapPasswordAuthenticator in component sshd-ldap
| in Apache MINA SSHD versions 1.2.0 to 2.19.0 or 3.0.0-M1 to 3.0.0-M5
| bypassed authentication checks.     Apache MINA SSHD is a Java
| library for client-side and server-side SSH. The optional sshd-ldap
| component provides support for integrating password and publickey
| authentication on the server side with an LDAP server.     sshd-ldap
| is an optional component. SSH servers implemented with Apache MINA
| SSHD are affected only if they use sshd-ldap and do configure an
| LdapPasswordAuthenticator to be used for password authentication.
| Normal password authentication via the built-in mechanisms in sshd-
| core is _not_ affected by this vulnerability, which concerns only
| LdapPasswordAuthenticator.     Users are recommended to upgrade
| affected applications to version 2.20.0 or 3.0.0-M6, which fix this
| issue.


CVE-2026-94053[7]:
| Authentication bypass via LDAP injection in component sshd-ldap in
| Apache MINA SSHD versions 1.2.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5.
| Apache MINA SSHD is a Java library for client-side and server-side
| SSH.  The optional sshd-ldap component provides support for
| integrating  password and publickey authentication on the server
| side with an LDAP  server.     sshd-ldap is an optional component.
| SSH servers implemented with Apache  MINA SSHD are affected only if
| they use sshd-ldap and do configure it to be used for password of
| public key authentication.  Other Apache MINA SSHD servers are not
| affected.     Lack of escaping LDAP filter metacharacters enabled
| successful authentication with username "*" and password "*".
| Users are recommended to upgrade affected applications to version
| 2.20.0 or 3.0.0-M6, which fix this issue by properly escaping filter
| parameters according to RFC 4515.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-77185
https://www.cve.org/CVERecord?id=CVE-2026-77185
[1] https://security-tracker.debian.org/tracker/CVE-2026-93994
https://www.cve.org/CVERecord?id=CVE-2026-93994
[2] https://security-tracker.debian.org/tracker/CVE-2026-93995
https://www.cve.org/CVERecord?id=CVE-2026-93995
[3] https://security-tracker.debian.org/tracker/CVE-2026-93996
https://www.cve.org/CVERecord?id=CVE-2026-93996
[4] https://security-tracker.debian.org/tracker/CVE-2026-94002
https://www.cve.org/CVERecord?id=CVE-2026-94002
[5] https://security-tracker.debian.org/tracker/CVE-2026-94029
https://www.cve.org/CVERecord?id=CVE-2026-94029
[6] https://security-tracker.debian.org/tracker/CVE-2026-94052
https://www.cve.org/CVERecord?id=CVE-2026-94052
[7] https://security-tracker.debian.org/tracker/CVE-2026-94053
https://www.cve.org/CVERecord?id=CVE-2026-94053

Regards,
Salvatore