Skip to content
VulniPulse
Highest advisory severityMedium 2 vendors · 2 advisories

CVE-2026-94029

CVE-2026-94029: 2 tracked advisory records across Apache, Red Hat. Compare vendor sources and published fix guidance.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Apache

1 advisory
  • Advisory severityMedium6.5

    Medium [CVE-2026-94029] Server-side memory exhaustion in Apache MINA SSHD 1.0.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5, component sshd-sftp, in the SFTP v6 check-file-name/check-file-handle extension

    CVE-2026-94029Source published Source updated

    Server-side memory exhaustion in Apache MINA SSHD 1.0.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5, component sshd-sftp, in the SFTP v6 check-file-name/check-file-handle extension. Apache MINA SSHD is a Java library for client-side and server-side SSH. Using a very small "block size" (for instance 256, which is the minimum) on a huge file generates many (file size / block size) hashes. The resulting SFTP reply message was accumulated fully in memory server-side, which could, with a suitably large (possibly sparse) file exhaust the server-side memory, taking down the server. Users are recommended to upgrade to version 2.20.0 or 3.0.0-M6, which fix this issue by imposing a maximum limit on the size of the reply. Many SFTP implementations have a general limit on the size of SFTP messages anyway…

    Affected products in this advisory
    • Apache MINA SSHD
    Source-reported affected versions
    • Apache MINA SSHD 1.0.0 before 2.20.0
    • Apache MINA SSHD 3.0.0-M1 before 3.0.0-M6
    Source-reported fixed versions
    • 2.20.0
    • 3.0.0-M6
    Mitigation guidance
    • Users are recommended to upgrade to version 2.20.0 or 3.0.0-M6, which fix this issue by imposing a maximum limit on the size of the reply.
    • Many SFTP implementations have a general limit on the size of SFTP messages anyway; typically 256kB as in OpenSSH or also in Apache MINA SSHD.
    Workarounds
    • Using a very small "block size" (for instance 256, which is the minimum) on a huge file generates many (file size / block size) hashes.

Red Hat

1 advisory
  • Advisory severityMedium6.5

    Medium [CVE-2026-94029] Denial of Service via memory exhaustion in SFTP check-file extension

    CVE-2026-94029Source published Source updated

    Denial of Service via memory exhaustion in SFTP check-file extension. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-770. Affected products named by the advisory: Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Apache Camel for Spring Boot 4; Red Hat build of Apicurio Registry 3; Red Hat Fuse 7.

    Related products — impact not confirmed
    • Red Hat build of Apache Camel 4 for Quarkus 3
    • Red Hat build of Apache Camel for Spring Boot 4
    • Red Hat build of Apicurio Registry 3
    • Red Hat Fuse 7
    Source-reported affected versions
    Affected-version details not available in this record.
    Source-reported fixed versions
    No fixed-version detail extracted. This does not mean no fix exists.
    Mitigation guidance
    • There is no mitigation available for this issue. Apply updates as they become available from Red Hat product teams. As a temporary workaround, consider implementing resource limits at the OS level (ulimit, cgroups) to prevent a single process from exhausting all available memory, or restrict SFTP access to trusted users only.

Android app · Google Play

Turn CVE research into alerts on your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery