Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-56452

Gravedad CVSS v3.1:
ALTA
Tipo:
CWE-22 Limitación incorrecta de nombre de ruta a un directorio restringido (Path Traversal)
Fecha de publicación:
20/07/2026
Última modificación:
27/07/2026

Descripción

*** Pendiente de traducción *** Path traversal in the sshd-scp component of Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side and server-side SSH.<br /> <br /> <br /> <br /> <br /> The implementation of receiving files or directories via SCP did not validate filenames in SCP "C" or "D" commands. A malicious sender could send filenames containing paths, resulting in files to be written in attacker-controlled places.<br /> <br /> <br /> <br /> <br /> The issue affects only<br /> <br /> * applications that use no longer supported Apache MINA SSHD versions = 2.0.0 to receive files.<br /> <br /> <br /> <br /> <br /> Applications using Apache MINA SSHD &gt;= 2.0.0 not using sshd-scp are not affected.<br /> <br /> <br /> <br /> <br /> The issue is fixed in Apache MINA 2.19.0 and 3.0.0-M5. Affected applications are advised to upgrade to these versions.

Productos y versiones vulnerables

CPE Desde Hasta
cpe:2.3:a:apache:mina_sshd:*:*:*:*:*:*:*:* 2.0.0 (incluyendo) 2.19.0 (excluyendo)
cpe:2.3:a:apache:mina_sshd:3.0.0:m1:*:*:*:*:*:*
cpe:2.3:a:apache:mina_sshd:3.0.0:m2:*:*:*:*:*:*
cpe:2.3:a:apache:mina_sshd:3.0.0:m3:*:*:*:*:*:*
cpe:2.3:a:apache:mina_sshd:3.0.0:m4:*:*:*:*:*:*