Apache MINA SSHD 版本 1.2.0 至 2.19.0,或 3.0.0-M1 至 3.0.0-M5 中, 组件里的 存在一个缺失的检查,导致可以绕过身份验证检查。 Apache MINA SSHD 是一个用于客户端和服务器端 SSH 的 Java 库。可选的 组件支持在服务器端将密码认证和公钥认证与 LDAP 服务器集成。 是一个可选组件。仅当使用 Apache MINA SSHD 实现的 SSH 服务器启用了 ,并配置了用于密码认证的 时,才会受到此漏洞的影响。通过 内置机制进行的常规密码认证不受此
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache MINA SSHD | 1.2.0 ~ 2.20.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-102508 | 9.2 CRITICAL | Apache PLC4X: OPC UA secure channel: integrity bypass, unverifiable server certificate, an |
| CVE-2026-94053 | 9.1 CRITICAL | Apache MINA SSHD: LDAP injection in sshd-ldap |
| CVE-2026-77185 | 9.1 CRITICAL | Apache MINA SSHD: Asynchronous authentication can bypass signature verification |
| CVE-2026-102510 | 8.7 HIGH | Apache PLC4X: Go binding: unbounded allocation and framing failures on wire-controlled len |
| CVE-2026-102509 | 8.7 HIGH | Apache PLC4X, Apache PLC4X: Pre-authentication resource exhaustion in the OPC UA driver an |
| CVE-2026-102511 | 8.5 HIGH | Apache PLC4X, Apache PLC4X, Apache PLC4X, Apache PLC4X: ADS discovery accepts spoofed resp |
| CVE-2026-93994 | 8.1 HIGH | Apache MINA SSHD: Repeated-publickey policy bypass on server |
| CVE-2026-94002 | 7.5 HIGH | Apache MINA SSHD: Memory exhaustion in SFTP client via unsolicited SFTP replies |
| CVE-2026-93995 | 6.5 MEDIUM | Apache MINA SSHD: Remote execution of JGit "archive -o=file.zip" can write file on the ser |
| CVE-2026-93996 | 6.5 MEDIUM | Apache MINA SSHD: Memory exhaustion DoS via unbounded SCP command line read |
| CVE-2026-94029 | 6.5 MEDIUM | Apache MINA SSHD: Memory exhaustion in SFTP v6 check-file-name/check-file-handle extension |
| CVE-2026-89238 | Apache WSS4J: WSS4J EncryptedHeader child confusion causing wrong protected-header selecti | |
| CVE-2026-88920 | Apache WSS4J: SAML Sender-Vouches Authentication Bypass | |
| CVE-2026-87830 | Apache WSS4J: Streaming WS-SecurityPolicy validation may skip element-protection checks. | |
| CVE-2026-85532 | Apache WSS4J: Insufficient Validation of Derived-Key Parameters | |
| CVE-2026-92121 | Apache WSS4J: WS-SecurityPolicy signature checks skipped in the streaming code after an ST | |
| CVE-2026-95616 | Apache WSS4J: Unauthenticated denial of service via integer overflow in DER parsing of X.5 | |
| CVE-2026-92899 | Apache WSS4J: UsernameToken replay protection bypassed by re-encoding the Nonce |
No comments yet