Executive brief
Apache MINA SSHD is a Java library used to build SSH clients and servers. A security flaw in its Git server component allows authenticated users to access files and repositories outside of their authorized directory when the server is running on Windows. This could lead to the exposure of sensitive source code or unauthorized access to private Git data.
Technical details
A path traversal vulnerability (CWE-22) exists in the sshd-git component of Apache MINA SSHD. The vulnerability specifically affects Git servers implemented with this library when hosted on Windows operating systems. While a previous fix (CVE-2026-48827) was implemented in versions 2.18.0 and 3.0.0-M4, the path validation was found to be ineffective for Windows-style file paths. An authenticated remote attacker can exploit this to bypass directory restrictions and access Git repositories outside the configured server-side root. The issue is resolved in versions 2.19.0 and 3.0.0-M5.
Affected products
- Apache Software Foundation Apache MINA SSHD 2.0.0 to 2.18.0, 3.0.0-M1 to 3.0.0-M4
Timeline
- 2026-07-20: advisory: NVD publication date
- 2026-07-20: disclosed: Apache Software Foundation disclosure