CVE-2026-56452
published 2026-07-20CVE-2026-56452: Path traversal in the sshd-scp component of Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side and server-side SSH. The implementation of…
PriorityP351high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
0.51%
41.5th percentile
Path traversal in the sshd-scp component of Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side and server-side SSH.
The implementation of receiving files or directories via SCP did not validate filenames in SCP "C" or "D" commands. A malicious sender could send filenames containing paths, resulting in files to be written in attacker-controlled places.
The issue affects only
* applications that use no longer supported Apache MINA SSHD versions = 2.0.0 to receive files.
Applications using Apache MINA SSHD >= 2.0.0 not using sshd-scp are not affected.
The issue is fixed in Apache MINA 2.19.0 and 3.0.0-M5. Affected applications are advised to upgrade to these versions.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | mina_sshd | — | — |
| apache | mina_sshd | — | — |
| apache | mina_sshd | — | — |
| apache | mina_sshd | — | — |
| apache | mina_sshd | >= 2.0.0 < 2.19.0 | 2.19.0 |
| apache_software_foundation | apache_mina_sshd | <= 2.18.0 | — |
| apache_software_foundation | apache_mina_sshd | 3.0.0-M1 – 3.0.0-M4 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Apache MINA SSHD up to 2.18.0/3.0.0-M4 sshd-scp path traversal
vuldb·2026-07-20·CVSS 7.5
CVE-2026-56452 [HIGH] Apache MINA SSHD up to 2.18.0/3.0.0-M4 sshd-scp path traversal
A vulnerability was found in Apache MINA SSHD up to 2.18.0/3.0.0-M4. It has been declared as critical. Affected is an unknown function of the component sshd-scp. Executing a manipulation can lead to path traversal.
The identification of this vulnerability is CVE-2026-56452. The attack may be launched remotely. There is no exploit available.
GHSA
Path traversal in the sshd-scp component of Apache MINA SSHD.
ghsa_unreviewed·2026-07-20
CVE-2026-56452 [HIGH] CWE-22 Path traversal in the sshd-scp component of Apache MINA SSHD.
Path traversal in the sshd-scp component of Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side and server-side SSH.
The implementation of receiving files or directories via SCP did not validate filenames in SCP "C" or "D" commands. A malicious sender could send filenames containing paths, resulting in files to be written in attacker-controlled places.
The issue affects only
* applications that use no longer supported Apache MINA SSHD versions = 2.0.0 to receive files.
Applications using Apache MINA SSHD >= 2.0.0 not using sshd-scp are not affected.
The issue is fixed in Apache MINA 2.19.0 and 3.0.0-M5. Affected applications are advised to upgrade to these versions.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-56452 jline: Apache MINA SSHD: Path traversal via SCP allows arbitrary file write [fedora-all]
bugzilla·2026-08-24·CVSS 7.5
CVE-2026-56452 [HIGH] CVE-2026-56452 jline: Apache MINA SSHD: Path traversal via SCP allows arbitrary file write [fedora-all]
CVE-2026-56452 jline: Apache MINA SSHD: Path traversal via SCP allows arbitrary file write [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Path traversal in the sshd-scp component of Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side and server-side SSH.
The implementation of receiving files or directories via SCP did not validate filenames in SCP "C" or "D" commands. A malicious sender could send filenames containing paths, resulting in files to be written in attacker-controlled places.
The issue affects only
* applications that use no longer supported Apache MINA SSHD versions
Bugzilla
CVE-2026-56452 apache-sshd: Apache MINA SSHD: Path traversal via SCP allows arbitrary file write [fedora-all]
bugzilla·2026-08-24·CVSS 7.5
CVE-2026-56452 [HIGH] CVE-2026-56452 apache-sshd: Apache MINA SSHD: Path traversal via SCP allows arbitrary file write [fedora-all]
CVE-2026-56452 apache-sshd: Apache MINA SSHD: Path traversal via SCP allows arbitrary file write [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Path traversal in the sshd-scp component of Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side and server-side SSH.
The implementation of receiving files or directories via SCP did not validate filenames in SCP "C" or "D" commands. A malicious sender could send filenames containing paths, resulting in files to be written in attacker-controlled places.
The issue affects only
* applications that use no longer supported Apache MINA SSHD ver
Bugzilla
CVE-2026-56452 org.apache.sshd/sshd-scp: Apache MINA SSHD: Path traversal via SCP allows arbitrary file write
bugzilla·2026-07-20·CVSS 7.5
CVE-2026-56452 [HIGH] CVE-2026-56452 org.apache.sshd/sshd-scp: Apache MINA SSHD: Path traversal via SCP allows arbitrary file write
CVE-2026-56452 org.apache.sshd/sshd-scp: Apache MINA SSHD: Path traversal via SCP allows arbitrary file write
Path traversal in the sshd-scp component of Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side and server-side SSH.
The implementation of receiving files or directories via SCP did not validate filenames in SCP "C" or "D" commands. A malicious sender could send filenames containing paths, resulting in files to be written in attacker-controlled places.
The issue affects only
* applications that use no longer supported Apache MINA SSHD versions = 2.0.0 to receive files.
Applications using Apache MINA SSHD >= 2.0.0 not using sshd-scp are not affected.
The issue is fixed in Apache MINA 2.19.0 and 3.0.0-M5. Affected applications are advised to upgrade to thes
2026-07-20
Published