Security update for apache-sshd, jpgpj
This update for apache-sshd, jpgpj fixes the following issues
Changes for jpgpj:
Changes for apache-sshd:
+ GH-743 Ensure the Java ServiceLoader use a singleton
SftpFileSystemProvider
+ GH-879 Close SSH channel gracefully on exception in port
forwarding
+ Security: Improve handling of repository paths in sshd-git.
Resolves CVE-2026-48827, bsc#1267018
+ GH-892 Align handling certificates without principals with
OpenSSH 10.3
+ GH-875 Use Apache Parent POM 36
+ GH-469, SSHD-897 Fix duplicate character echo with interactive
shells
+ GH-721 SSH client: schedule session timeout checks on demand
only
+ GH-807 Handle 'verified' flag for sk-* keys
+ GH-809 Fix server-side authentication for FIDO/U2F sk-* keys
with flags in authorized_keys
+ GH-827 Don't fail on invalid known_hosts lines; log and skip
them
+ GH-830 EC public keys: let Bouncy Castle generate X.509
encodings with the curve OID as algorithm parameter
+ GH-855 SFTP: use a single SftpClient per SftpFileSystem
+ GH-856 Fix using ed25519 with BC-FIPS
+ GH-861 SFTP client: prevent sending zero-length writes in
SftpOutputStreamAsync
+ SSHD-1348 Fix zero-length SFTP reads
+ SSHD-1349 Bump PMD to 7.20.0 to avoid StackOverflowError when
compiling on Java 26-ea
+ GH-814 Include a fix for CVE-2020-36843 (bsc#1239551) in
optional dependency net.i2p.crypto:eddsa:0.3.0: perform the
missing range check in Apache MINA SSHD before delegating to
the signature verification in net.i2p.crypto:eddsa:0.3.0.
This means that using net.i2p.crypto:eddsa:0.3.0 in Apache
MINA SSHD is safe despite that CVE in the dependency.
+ GH-865 replace %h in HostName SSH config
+ bugfix: fix cert auth failed bug
+ GH-664: Skip MAC negotiation if an AEAD cipher was negotiated
+ GH-663: Fix a race in IoSession creation
+ Also test sshd-mina using mina-core 2.2.4
+ ScpShell fixes; SFTP append mode for buggy servers
+ fix sources.jar Reproducible Builds issue
+ GH-700: Fix race in AbstractCloseable.doCloseImmediately()
+ GH-705: Make ChannelToPortHandler accessible to user code
+ GH-709: Handle keep-alive channel messages sent by an old
OpenSSH server
+ GH-727: supply default port for proxyJump if no
HostConfigEntry
+ GH-733: Fix SftpRemotePathChannel.transferTo
+ GH-725: Added commandTimeoutMillis in executeRemoteCommand
+ GH-774: Fix WritePendingException
+ #771 Avoid NoClassDefFoundError:
net/i2p/crypto/eddsa/EdDSAPublicKey
+ GH-516: Fix filesystem-id parsing in getFileSystem(URI)
+ GH-754: Don't close DefaultForwarder on bind error
+ Close repository after usage in GitPackCommand
+ Trigger ClientChannelEvent.Timeout and
ClientSessionEvent.TIMEOUT independently to host's program
cycle times
+ GH-618: Fix reading an OpenSshCertificate from a Buffer
+ Add interface to configure details of JGit's pack
implementation
+ ML-KEM key exchanges using Bouncy Castle 1.79
+ GH-628: Fix reading directories with trailing blanks in the
name
+ GH-626: Enable Streaming.Async for ChannelDirectTcpip
+ Sftp server 'ls' command timeout
+ GH-636: Handle unknown key types in known_hosts
+ GH-643: provide interfaces for caching file attributes on
paths
+ Bouncy Castle EdDSA / Ed25519 Support
+ Abstract revoked key handling in KnownHostsServerKeyVerifier
+ GH-524 Performance improvements
+ GH-533 Fix multi-step authentication
+ GH-582 Fix filtering in NamedFactory
+ GH-587 Prevent NullPointerExceptionon closed channel in
NettyIoSession
+ GH-590 Better support for FIPS
+ GH-597 Pass on Charset in
ClientSession.executeRemoteCommand()
+ New utility methods SftpClient.put(Path localFile, String
remoteFileName) and SftpClient.put(InputStream in, String
remoteFileName) facilitate SFTP file uploading.
Besides fixing a bug with bc-fips (the RandomGenerator class
exists in normal Bouncy Castle, but not in the FIPS version,
but Apache MINA sshd referenced it even if only bc-fips was
present), support was improved for running in an environment
restricted by FIPS.
There is a new system property
org.apache.sshd.security.fipsEnabled. If set to true, a number
of crypto-algorithms not approved by FIPS 140 are disabled:
+ key exchange methods sntrup761x25519-sha512,
[email protected], curve25519-sha256,
SUSE-SU-2026:2472-1 is recorded against 2 packages.
Published on 19 June 2026 and last revised on 20 June 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.
www.suse.com (Advisory)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
www.suse.com (Web)
www.suse.com (Web)
Details
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| apache-sshd | — | 2.18.0-150200.5.11.1 |
| jpgpj | — | 1.3-150200.5.3.1 |
References
Similar Threats
Free Vulnerability Check
BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against SUSE-SU-2026:2472-1 and other known CVE records.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.