CVE-2026-56452

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
20/07/2026
Last modified:
27/07/2026

Description

Path traversal in the sshd-scp component of Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side and server-side SSH.<br /> <br /> <br /> <br /> <br /> The implementation of receiving files or directories via SCP did not validate filenames in SCP "C" or "D" commands. A malicious sender could send filenames containing paths, resulting in files to be written in attacker-controlled places.<br /> <br /> <br /> <br /> <br /> The issue affects only<br /> <br /> * applications that use no longer supported Apache MINA SSHD versions = 2.0.0 to receive files.<br /> <br /> <br /> <br /> <br /> Applications using Apache MINA SSHD &gt;= 2.0.0 not using sshd-scp are not affected.<br /> <br /> <br /> <br /> <br /> The issue is fixed in Apache MINA 2.19.0 and 3.0.0-M5. Affected applications are advised to upgrade to these versions.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:mina_sshd:*:*:*:*:*:*:*:* 2.0.0 (including) 2.19.0 (excluding)
cpe:2.3:a:apache:mina_sshd:3.0.0:m1:*:*:*:*:*:*
cpe:2.3:a:apache:mina_sshd:3.0.0:m2:*:*:*:*:*:*
cpe:2.3:a:apache:mina_sshd:3.0.0:m3:*:*:*:*:*:*
cpe:2.3:a:apache:mina_sshd:3.0.0:m4:*:*:*:*:*:*