cbcvebase.

Apache Software Foundation Apache Mina Sshd vulnerabilities

8 known vulnerabilities affecting apache_software_foundation/apache_mina_sshd.

Total CVEs
8
CISA KEV
0
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL1HIGH3MEDIUM4

Vulnerabilities

Page 1 of 1
CVE-2023-48795P1MEDIUMCVSS 5.9ExploitedPoC≤ 2.11.02023-12-18
CVE-2023-48795 [MEDIUM] CWE-354 CVE-2023-48795: The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other pr The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some security features have been downgr
nvd
CVE-2022-45047P3CRITICALCVSS 9.8≥ unspecified, ≤ 2.9.12022-11-16
CVE-2022-45047 [CRITICAL] CWE-502 CVE-2022-45047: Class org.apache.sshd.server.keyprovider.SimpleGeneratorHostKeyProvider in Apache MINA SSHD <= 2.9.1 Class org.apache.sshd.server.keyprovider.SimpleGeneratorHostKeyProvider in Apache MINA SSHD <= 2.9.1 uses Java deserialization to load a serialized java.security.PrivateKey. The class is one of several implementations that an implementor using Apache MINA SSHD can choose for loading the host keys of an SSH server.
nvd
CVE-2026-56452P3HIGHCVSS 7.5≤ 2.18.0≥ 3.0.0-M1, ≤ 3.0.0-M42026-07-20
CVE-2026-56452 [HIGH] CWE-22 CVE-2026-56452: Path traversal in the sshd-scp component of Apache MINA SSHD. Apache MINA SSHD is a Java library for Path traversal in the sshd-scp component of Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side and server-side SSH. The implementation of receiving files or directories via SCP did not validate filenames in SCP "C" or "D" commands. A malicious sender could send filenames containing paths, resulting in files to be written in attacker
nvd
CVE-2026-56624P3HIGHCVSS 7.3≥ 2.0.0, ≤ 2.18.0≥ 3.0.0-M1, ≤ 3.0.0-M42026-07-20
CVE-2026-56624 [HIGH] CWE-295 CVE-2026-56624: Improper certificate validation in Apache MINA SSHD (server-side). Apache MINA SSHD is a Java librar Improper certificate validation in Apache MINA SSHD (server-side). Apache MINA SSHD is a Java library for client-side and server-side SSH. Server-side OpenSSH user certificate validation during user authentication in an Apache MINA SSHD server did not check for the unsupported force-command or verify-required options that could be embedded in the ce
nvd
CVE-2026-48827P3HIGHCVSS 7.1≥ 2.0.0, ≤ 2.18.0≥ 3.0.0-M1, ≤ 3.0.0-M42026-06-01
CVE-2026-48827 [HIGH] CWE-22 CVE-2026-48827: Path traversal vulnerability in Apache MINA SSHD bundle sshd-git. Lack of path validation in git-upl Path traversal vulnerability in Apache MINA SSHD bundle sshd-git. Lack of path validation in git-upload-pack, git-receive-pack, and other git operations allows users authenticated over SSH access to git repositories outside the configured git server root directory. Applications are affected if they use org.apache.sshd:sshd-git. Applications not using
nvd
CVE-2021-30129P3MEDIUMCVSS 6.5≥ 2.0.0, < Apache Mina SSHD*2021-07-12
CVE-2021-30129 [MEDIUM] CWE-772 CVE-2021-30129: A vulnerability in sshd-core of Apache Mina SSHD allows an attacker to overflow the server causing a A vulnerability in sshd-core of Apache Mina SSHD allows an attacker to overflow the server causing an OutOfMemory error. This issue affects the SFTP and port forwarding features of Apache Mina SSHD version 2.0.0 and later versions. It was addressed in Apache Mina SSHD 2.7.0
nvd
CVE-2026-58624P3MEDIUMCVSS 5.4≥ 2.0.0, ≤ 2.18.0≥ 3.0.0-M1, ≤ 3.0.0-M42026-07-20
CVE-2026-58624 [MEDIUM] CWE-20 CVE-2026-58624: Improper input validation in sshd-git in Apache MINA SSHD. Apache MINA SSHD is a Java library for cl Improper input validation in sshd-git in Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side and server-side SSH. Component org.apache.sshd:sshd-git provides though its GitPgmCommandFactory a way to configure an Apache MINA SSHD server such that SSH clients can remotely execute git commands via the JGit library on git repositories
nvd
CVE-2023-35887P4MEDIUMCVSS 4.3≥ 1.0, < 2.102023-07-10
CVE-2023-35887 [MEDIUM] CWE-22 CVE-2023-35887: Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundati Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache MINA. In SFTP servers implemented using Apache MINA SSHD that use a RootedFileSystem, logged users may be able to discover "exists/does not exist" information about items outside the rooted tree via paths including parent navigation ("..") b
nvd