Directory Traversal Affecting libmina-sshd-java package, versions *


Severity

Recommended
low

Based on default assessment until relevant scores are available.

Threat Intelligence

EPSS
0.53% (41st percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-ECHOLATEST-LIBMINASSHDJAVA-18507882
  • published2 Aug 2026
  • disclosed1 Jun 2026

Introduced: 1 Jun 2026

CVE-2026-48827  (opens in a new tab)
CWE-22  (opens in a new tab)

How to fix?

There is no fixed version for Echo:latest libmina-sshd-java.

NVD Description

Note: Versions mentioned in the description apply only to the upstream libmina-sshd-java package and not the libmina-sshd-java package as distributed by Echo. See How to fix? for Echo:latest relevant fixed versions and status.

Path traversal vulnerability in Apache MINA SSHD bundle sshd-git. Lack of path validation in git-upload-pack, git-receive-pack, and other git operations allows users authenticated over SSH access to git repositories outside the configured git server root directory.

Applications are affected if they use org.apache.sshd:sshd-git. Applications not using sshd-git are not affected.

Users are advised to upgrade affected applications to Apche MINA SSHD 2.18.0, which fixes the issue.

The issue also is present in the pre-release milestones 3.0.0-M1 to 3.0.0-M3 for a new upcoming new major version 3.0.0. Again, applications are affected only if they use sshd-git. Upgrade affected applications to 3.0.0-M4.

We would like to point out that a professional git server should not rely solely on file system layout and permissions, but should implement additional security controls to govern access to git repositories and operations allowed on particular git repositories.

CVSS Base Scores

version 3.1