CVE-2026-56452
Published:July 20, 2026
Updated:July 21, 2026
Path traversal in the sshd-scp component of Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side and server-side SSH.
The implementation of receiving files or directories via SCP did not validate filenames in SCP "C" or "D" commands. A malicious sender could send filenames containing paths, resulting in files to be written in attacker-controlled places.
The issue affects only
* applications that use no longer supported Apache MINA SSHD versions < 2.0.0 and use the SCP functions to receive files,
* or applications using sshd-scp in Apache MINA SSHD >= 2.0.0 to receive files.
Applications using Apache MINA SSHD >= 2.0.0 not using sshd-scp are not affected.
The issue is fixed in Apache MINA 2.19.0 and 3.0.0-M5. Affected applications are advised to upgrade to these versions.
Affected Packages
https://github.com/apache/mina-sshd.git (GITHUB):
Affected version(s) >=sshd-2.0.0 <sshd-2.19.0Fix Suggestion:
Update to version sshd-2.19.0https://github.com/apache/mina-sshd.git (GITHUB):
Affected version(s) >=sshd-3.0.0-M1 <sshd-3.0.0-M5Fix Suggestion:
Update to version sshd-3.0.0-M5org.apache.sshd:sshd-scp (JAVA):
Affected version(s) >=2.0.0 <2.19.0Fix Suggestion:
Update to version 2.19.0org.apache.sshd:sshd-scp (JAVA):
Affected version(s) >=3.0.0-M1 <3.0.0-M5Fix Suggestion:
Update to version 3.0.0-M5Related Resources (2)
Do you need more information?
Contact UsCVSS v4
Base Score:
8.7
Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
Vulnerable System Confidentiality
NONE
Vulnerable System Integrity
HIGH
Vulnerable System Availability
NONE
Subsequent System Confidentiality
NONE
Subsequent System Integrity
NONE
Subsequent System Availability
NONE
CVSS v3
Base Score:
7.5
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
HIGH
Availability
NONE
Weakness Type (CWE)
EPSS
Base Score:
0.36