You are viewing this page in an unauthorized frame window.
This is a potential security issue, you are being redirected to
https://nvd.nist.gov
An official website of the United States government
Official websites use .gov
A .gov website belongs to an official government organization in the United States.
Secure .gov websites use HTTPS
A lock () or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.
Path traversal vulnerability in Apache MINA SSHD bundle sshd-git. Lack of path validation in git-upload-pack, git-receive-pack, and other git operations allows users authenticated over SSH access to git repositories outside the configured git server root directory.
Applications are affected if they use org.apache.sshd:sshd-git. Applications not using sshd-git are not affected.
Users are advised to upgrade affected applications to Apche MINA SSHD 2.18.0, which fixes the issue.
The issue also is present in the pre-release milestones 3.0.0-M1 to 3.0.0-M3 for a new upcoming new major version 3.0.0. Again, applications are affected only if they use sshd-git. Upgrade affected applications to 3.0.0-M4.
We would like to point out that a professional git server should not rely solely on file system layout and permissions, but should implement additional security controls to govern access to git repositories and operations allowed on particular git repositories.
Metrics
NVD enrichment efforts reference publicly available information to associate
vector strings. CVSS information contributed by other sources is also
displayed.
By selecting these links, you will be leaving NIST webspace.
We have provided these links to other web sites because they
may have information that would be of interest to you. No
inferences should be drawn on account of other sites being
referenced, or not, from this page. There may be other web
sites that are more appropriate for your purpose. NIST does
not necessarily endorse the views expressed, or concur with
the facts presented on these sites. Further, NIST does not
endorse any commercial products that may be mentioned on
these sites. Please address comments about this page to [email protected].
Title: Apache MINA SSHD de Apache Software Foundation, Description: Vulnerabilidad de salto de ruta en el paquete Apache MINA SSHD sshd-git. La falta de validación de ruta en git-upload-pack, git-receive-pack y otras operaciones de git permite a los usuarios autenticados por SSH acceder a repositorios git fuera del directorio raíz del servidor git configurado.
Las aplicaciones se ven afectadas si utilizan org.apache.sshd:sshd-git. Las aplicaciones que no utilizan sshd-git no se ven afectadas.
Se aconseja a los usuarios actualizar las aplicaciones afectadas a Apache MINA SSHD 2.18.0, que soluciona el problema.
El problema también está presente en los hitos de prelanzamiento 3.0.0-M1 a 3.0.0-M3 para una nueva versión principal próxima 3.0.0. De nuevo, las aplicaciones se ven afectadas solo si utilizan sshd-git. Actualice las aplicaciones afectadas a 3.0.0-M4.
Nos gustaría señalar que un servidor git profesional no debe depender únicamente del diseño y los permisos del sistema de archivos, sino que debe implementar controles de seguridad adicionales para gobernar el acceso a los repositorios git y las operaciones permitidas en repositorios git particulares.
CVE Modified by Apache Software Foundation6/17/2026 6:55:15 AM
Action
Type
Old Value
New Value
Added
Affected
[{"vendor":"Apache Software Foundation","product":"Apache MINA SSHD","defaultStatus":"unaffected","collectionURL":"https://repo.maven.apache.org/maven2","packageName":"org.apache.sshd:sshd-git","versions":[{"version":"2.0.0","lessThanOrEqual":"2.17.1","versionType":"maven","status":"affected"},{"version":"3.0.0-M1","lessThanOrEqual":"3.0.0-M3","versionType":"maven","status":"affected"}]}]
Initial Analysis by NIST6/01/2026 1:08:05 PM
Action
Type
Old Value
New Value
Added
CPE Configuration
OR
*cpe:2.3:a:apache:mina_sshd:*:*:*:*:*:*:*:* versions from (including) 2.0.0 up to (excluding) 2.18.0
*cpe:2.3:a:apache:mina_sshd:3.0.0:m1:*:*:*:*:*:*
*cpe:2.3:a:apache:mina_sshd:3.0.0:m2:*:*:*:*:*:*
*cpe:2.3:a:apache:mina_sshd:3.0.0:m3:*:*:*:*:*:*
New CVE Received from Apache Software Foundation6/01/2026 5:16:20 AM
Action
Type
Old Value
New Value
Added
Description
Path traversal vulnerability in Apache MINA SSHD bundle sshd-git. Lack of path validation in git-upload-pack, git-receive-pack, and other git operations allows users authenticated over SSH access to git repositories outside the configured git server root directory.
Applications are affected if they use org.apache.sshd:sshd-git. Applications not using sshd-git are not affected.
Users are advised to upgrade affected applications to Apche MINA SSHD 2.18.0, which fixes the issue.
The issue also is present in the pre-release milestones 3.0.0-M1 to 3.0.0-M3 for a new upcoming new major version 3.0.0. Again, applications are affected only if they use sshd-git. Upgrade affected applications to 3.0.0-M4.
We would like to point out that a professional git server should not rely solely on file system layout and permissions, but should implement additional security controls to govern access to git repositories and operations allowed on particular git repositories.