Skip to main content

Boteraser | Website and Server Security Solutions

🛡️ SUSE-SU-2026:3339-1 — apache-sshd (CVE-2026-56452 +3 more)

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Security update for apache-sshd

This update for apache-sshd fixes the following issues:

Update to upstream version 2.19.0.

Security issues fixed:

  • CVE-2026-56452: remote users can use SCP to send filenames that lead to arbitrary file writes due to a path traversal

issue in the sshd-scp component of Apache MINA SSHD. (bsc#1272158).

  • CVE-2026-56623: remote users can obtain access to git repositories outside of the configured server-side root

directory on Windows systems due to path traversal issue in org.apache.sshd:sshd-git (bsc#1271993).

  • CVE-2026-56624: users can authenticate with certificates containing the force-command option but still execute

other commands due to improper validation of certificate options in Apache MINA SSHD (bsc#1271992).

  • CVE-2026-58624: remote execution of JGit commands can lead to arbitrary file writes due to improper input validation

in sshd-git of Apache MINA SSHD (bsc#1271991).

Other updates and bugfixes:

  • Version 2.19.0:
  • Bug Fixes

+ GH-899 Fix ProcessShellFactory on Linux.

+ GH-902 Fix client-side handling of sk-* public key signatures (also in the agent interfaces).

+ Limit size of decompressed SSH packets.

+ Improve checking SSH user certificates in public-key authentication.

+ Improve handling of repository paths in sshd-git on Windows.

+ Validate file names in SCP.

+ Escape newlines in filenames in the SCP protocol.

+ Restrict JGit commands accessible via GitPgmCommandFactory in sshd-git.

Affected software

SUSE-SU-2026:3339-1 is recorded against 1 package.

  • apache-sshd (fixed in 2.19.0-150200.5.16.1)

Timeline and source

Published on 28 July 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

www.suse.com (Advisory)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2026-07-28
Updated 2026-08-20
Modified 2026-07-28
Fix URL N/A

Affected Packages

Software From version Fixed in
apache-sshd 2.19.0-150200.5.16.1

Free Vulnerability Check

Is your site affected by SUSE-SU-2026:3339-1?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against SUSE-SU-2026:3339-1 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.