Skip to content
VulniPulse
Highest advisory severityHigh 2 vendors · 2 advisories

CVE-2026-94002

CVE-2026-94002: 2 tracked advisory records across Apache, Red Hat. Compare vendor sources and published fix guidance.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Apache

1 advisory
  • Advisory severityHigh7.5

    High [CVE-2026-94002] Possible memory exhaustion in SFTP clients (DefaultSftpClient) in component sshd-sftp in Apache MINA SSHD versions 0.9.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5

    CVE-2026-94002Source published Source updated

    Possible memory exhaustion in SFTP clients (DefaultSftpClient) in component sshd-sftp in Apache MINA SSHD versions 0.9.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5. MINA SSHD is a Java library for client-side and server-side SSH. The sshd-sftp component provides support for SFTP. The SFTP client implementation, when receiving a reply, did not check that this reply corresponded to a request sent earlier. Unsolicited replies would be stored but never consumed. A malicious server could keep sending unsolicited replies until available memory in the client was exhausted. Users are recommended to upgrade to version 2.20.0 or 3.0.0-M6, which fix this issue.

    Affected products in this advisory
    • Apache MINA SSHD
    Source-reported affected versions
    • Apache MINA SSHD 0.9.0 before 2.20.0
    • Apache MINA SSHD 3.0.0-M1 before 3.0.0-M6
    Source-reported fixed versions
    • 2.20.0
    • 3.0.0-M6
    Mitigation guidance
    • Users are recommended to upgrade to version 2.20.0 or 3.0.0-M6, which fix this issue.

Red Hat

1 advisory
  • Advisory severityHigh7.5

    High [CVE-2026-94002] Denial of Service via unsolicited SFTP replies

    CVE-2026-94002Source published Source updated

    Denial of Service via unsolicited SFTP replies. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected products named by the advisory: Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Apache Camel for Spring Boot 4; Red Hat build of Apicurio Registry 3; Red Hat Fuse 7.

    Related products — impact not confirmed
    • Red Hat build of Apache Camel 4 for Quarkus 3
    • Red Hat build of Apache Camel for Spring Boot 4
    • Red Hat build of Apicurio Registry 3
    • Red Hat Fuse 7
    Source-reported affected versions
    Affected-version details not available in this record.
    Source-reported fixed versions
    No fixed-version detail extracted. This does not mean no fix exists.
    Mitigation guidance
    No mitigation guidance extracted; consult the source.

Android app · Google Play

Turn CVE research into alerts on your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery