Improper Certificate Validation Affecting libmina-sshd-java package, versions *


Severity

Recommended
low

Based on default assessment until relevant scores are available.

Threat Intelligence

EPSS
0.18% (8th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-ECHOLATEST-LIBMINASSHDJAVA-18507884
  • published2 Aug 2026
  • disclosed20 Jul 2026

Introduced: 20 Jul 2026

NewCVE-2026-56624  (opens in a new tab)
CWE-295  (opens in a new tab)

How to fix?

There is no fixed version for Echo:latest libmina-sshd-java.

NVD Description

Note: Versions mentioned in the description apply only to the upstream libmina-sshd-java package and not the libmina-sshd-java package as distributed by Echo. See How to fix? for Echo:latest relevant fixed versions and status.

Improper certificate validation in Apache MINA SSHD (server-side). Apache MINA SSHD is a Java library for client-side and server-side SSH.

Server-side OpenSSH user certificate validation during user authentication in an Apache MINA SSHD server did not check for the unsupported force-command or verify-required options that could be embedded in the certificate, nor did it validate these options. As a result it was possible that a user could authenticate with such a certificate that included a force-command option but still was able to execute other commands. What other command exactly would be available to the user depends on the implementation of the server.

This issue is fixed in Apache MINA SSHD 2.19.0 and 3.0.0-M5. Applications are advised to upgrade to these versions.

The fix rejects OpenSSH user certificates that include these options, since Apache MINA SSHD implements neither force-command nor sk-*-cert-v01@openssh.com user certificates (which are the only ones for which verify-required would make sense).

CVSS Base Scores

version 3.1