CVE-2026-94029
CVE-2026-94029: 2 tracked advisory records across Apache, Red Hat. Compare vendor sources and published fix guidance.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Apache
1 advisory- Advisory severityMedium6.5
Medium [CVE-2026-94029] Server-side memory exhaustion in Apache MINA SSHD 1.0.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5, component sshd-sftp, in the SFTP v6 check-file-name/check-file-handle extension
CVE-2026-94029Source published Source updated
Server-side memory exhaustion in Apache MINA SSHD 1.0.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5, component sshd-sftp, in the SFTP v6 check-file-name/check-file-handle extension. Apache MINA SSHD is a Java library for client-side and server-side SSH. Using a very small "block size" (for instance 256, which is the minimum) on a huge file generates many (file size / block size) hashes. The resulting SFTP reply message was accumulated fully in memory server-side, which could, with a suitably large (possibly sparse) file exhaust the server-side memory, taking down the server. Users are recommended to upgrade to version 2.20.0 or 3.0.0-M6, which fix this issue by imposing a maximum limit on the size of the reply. Many SFTP implementations have a general limit on the size of SFTP messages anyway…
- Affected products in this advisory
- Apache MINA SSHD
- Source-reported affected versions
- Apache MINA SSHD 1.0.0 before 2.20.0
- Apache MINA SSHD 3.0.0-M1 before 3.0.0-M6
- Source-reported fixed versions
- 2.20.0
- 3.0.0-M6
- Mitigation guidance
- Users are recommended to upgrade to version 2.20.0 or 3.0.0-M6, which fix this issue by imposing a maximum limit on the size of the reply.
- Many SFTP implementations have a general limit on the size of SFTP messages anyway; typically 256kB as in OpenSSH or also in Apache MINA SSHD.
- Workarounds
- Using a very small "block size" (for instance 256, which is the minimum) on a huge file generates many (file size / block size) hashes.
Red Hat
1 advisory- Advisory severityMedium6.5
Medium [CVE-2026-94029] Denial of Service via memory exhaustion in SFTP check-file extension
CVE-2026-94029Source published Source updated
Denial of Service via memory exhaustion in SFTP check-file extension. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-770. Affected products named by the advisory: Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Apache Camel for Spring Boot 4; Red Hat build of Apicurio Registry 3; Red Hat Fuse 7.
- Related products — impact not confirmed
- Red Hat build of Apache Camel 4 for Quarkus 3
- Red Hat build of Apache Camel for Spring Boot 4
- Red Hat build of Apicurio Registry 3
- Red Hat Fuse 7
- Source-reported affected versions
- Affected-version details not available in this record.
- Source-reported fixed versions
- No fixed-version detail extracted. This does not mean no fix exists.
- Mitigation guidance
- There is no mitigation available for this issue. Apply updates as they become available from Red Hat product teams. As a temporary workaround, consider implementing resource limits at the OS level (ulimit, cgroups) to prevent a single process from exhausting all available memory, or restrict SFTP access to trusted users only.
Android app · Google Play
Turn CVE research into alerts on your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.