CVE-2026-56452
Gravedad CVSS v3.1:
ALTA
Tipo:
CWE-22
Limitación incorrecta de nombre de ruta a un directorio restringido (Path Traversal)
Fecha de publicación:
20/07/2026
Última modificación:
27/07/2026
Descripción
*** Pendiente de traducción *** Path traversal in the sshd-scp component of Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side and server-side SSH.<br />
<br />
<br />
<br />
<br />
The implementation of receiving files or directories via SCP did not validate filenames in SCP "C" or "D" commands. A malicious sender could send filenames containing paths, resulting in files to be written in attacker-controlled places.<br />
<br />
<br />
<br />
<br />
The issue affects only<br />
<br />
* applications that use no longer supported Apache MINA SSHD versions = 2.0.0 to receive files.<br />
<br />
<br />
<br />
<br />
Applications using Apache MINA SSHD >= 2.0.0 not using sshd-scp are not affected.<br />
<br />
<br />
<br />
<br />
The issue is fixed in Apache MINA 2.19.0 and 3.0.0-M5. Affected applications are advised to upgrade to these versions.
Impacto
Puntuación base 3.x
7.50
Gravedad 3.x
ALTA
Productos y versiones vulnerables
| CPE | Desde | Hasta |
|---|---|---|
| cpe:2.3:a:apache:mina_sshd:*:*:*:*:*:*:*:* | 2.0.0 (incluyendo) | 2.19.0 (excluyendo) |
| cpe:2.3:a:apache:mina_sshd:3.0.0:m1:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:mina_sshd:3.0.0:m2:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:mina_sshd:3.0.0:m3:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:mina_sshd:3.0.0:m4:*:*:*:*:*:* |
Para consultar la lista completa de nombres de CPE con productos y versiones, ver esta página



