cbcvebase.

Apache Mina Sshd vulnerabilities

7 known vulnerabilities affecting apache/mina_sshd.

Total CVEs
7
CISA KEV
0
Public exploits
1
Exploited in wild
1
Severity breakdown
HIGH4MEDIUM3

Vulnerabilities

Page 1 of 1
CVE-2019-6111P1MEDIUMCVSS 5.9ExploitedPoCRansomwarev2.2.02019-01-31
CVE-2019-6111 [MEDIUM] CWE-22 CVE-2019-6111: An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, t An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses which files/directories are sent to the client. However, the scp client only performs cursory validation of the object name returned (only directory traversal attacks are prevented). A malicious scp server (or Man-in-The-Middle attacker
nvd
CVE-2026-56452P3HIGHCVSS 7.5≥ 2.0.0, < 2.19.0v3.0.0-m1+3 more2026-07-20
CVE-2026-56452 [HIGH] CWE-22 CVE-2026-56452: Path traversal in the sshd-scp component of Apache MINA SSHD. Apache MINA SSHD is a Java library for Path traversal in the sshd-scp component of Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side and server-side SSH. The implementation of receiving files or directories via SCP did not validate filenames in SCP "C" or "D" commands. A malicious sender could send filenames containing paths, resulting in files to be written in attacker
nvd
CVE-2026-56624P3HIGHCVSS 7.3≥ 2.0.0, < 2.19.0v3.0.0-m1+3 more2026-07-20
CVE-2026-56624 [HIGH] CWE-295 CVE-2026-56624: Improper certificate validation in Apache MINA SSHD (server-side). Apache MINA SSHD is a Java librar Improper certificate validation in Apache MINA SSHD (server-side). Apache MINA SSHD is a Java library for client-side and server-side SSH. Server-side OpenSSH user certificate validation during user authentication in an Apache MINA SSHD server did not check for the unsupported force-command or verify-required options that could be embedded in the ce
nvd
CVE-2026-48827P3HIGHCVSS 7.1≥ 2.0.0, < 2.18.0v3.0.0-m1+2 more2026-06-01
CVE-2026-48827 [HIGH] CWE-22 CVE-2026-48827: Path traversal vulnerability in Apache MINA SSHD bundle sshd-git. Lack of path validation in git-upl Path traversal vulnerability in Apache MINA SSHD bundle sshd-git. Lack of path validation in git-upload-pack, git-receive-pack, and other git operations allows users authenticated over SSH access to git repositories outside the configured git server root directory. Applications are affected if they use org.apache.sshd:sshd-git. Applications not using
nvd
CVE-2026-56623P3HIGHCVSS 7.1≥ 2.0.0, < 2.19.0v3.0.0-m1+3 more2026-07-20
CVE-2026-56623 [HIGH] CVE-2026-56623: Path traversal on Windows in Apache MINA SSHD component sshd-git. Apache MINA SSHD is a Java library Path traversal on Windows in Apache MINA SSHD component sshd-git. Apache MINA SSHD is a Java library for client-side and server-side SSH. A git server implemented with Apache MINA SSHD component sshd-git and running on Windows could allow an authenticated remote user access to git repositories outside of the configured server-side root directory. The path v
nvd
CVE-2026-58624P3MEDIUMCVSS 5.4≥ 2.0.0, < 2.19.0v3.0.0-m1+3 more2026-07-20
CVE-2026-58624 [MEDIUM] CWE-20 CVE-2026-58624: Improper input validation in sshd-git in Apache MINA SSHD. Apache MINA SSHD is a Java library for cl Improper input validation in sshd-git in Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side and server-side SSH. Component org.apache.sshd:sshd-git provides though its GitPgmCommandFactory a way to configure an Apache MINA SSHD server such that SSH clients can remotely execute git commands via the JGit library on git repositories
nvd
CVE-2024-41909P4MEDIUMCVSS 5.9≤ 2.11.02024-08-12
CVE-2024-41909 [MEDIUM] CVE-2024-41909: Like many other SSH implementations, Apache MINA SSHD suffered from the issue that is more widely kn Like many other SSH implementations, Apache MINA SSHD suffered from the issue that is more widely known as CVE-2023-48795. An attacker that can intercept traffic between client and server could drop certain packets from the stream, potentially causing client and server to consequently end up with a connection for which some security features have been downg
nvd
Apache Mina Sshd vulnerabilities | cvebase