Apache disclosed CVE-2026-48827, a path traversal flaw in the org.apache.sshd:sshd-git bundle of Apache MINA SSHD that lets an SSH-authenticated user escape the configured Git root by supplying repository paths containing traversal sequences such as ../. The issue affects sshd-git versions 2.0.0 through 2.17.1 and 3.0.0-M1 through 3.0.0-M3, impacting git-upload-pack, git-receive-pack, and related operations. Successful exploitation can expose arbitrary Git repositories on the server filesystem and, in some cases, allow unauthorized writes outside the intended root. Apache fixed the bug in versions 2.18.0 and 3.0.0-M4 by adding centralized path validation, and noted that deployments using Apache MINA SSHD without the non-default sshd-git module are not affected.
Apache also disclosed CVE-2026-35563 in the Apache Directory LDAP API client, where versions 2.0.0 through 2.1.7 failed to verify whether a TLS server certificate matched the intended LDAP hostname. Because the client would accept a trusted certificate issued for an unrelated host, an attacker with man-in-the-middle network access could impersonate the LDAP server and fully compromise the connection. The flaw is tracked as CWE-297, and Apache said hostname verification is now enforced in a newer LDAP API release. The disclosures highlight two separate Apache security fixes affecting repository isolation in SSH-based Git services and certificate validation in LDAP client connections.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
CVE-2026-35563 was reported to security@apache.org on June 1, 2026. The issue involves missing hostname verification in LDAP client TLS checks, and Apache said a newer version enforces hostname verification.
Apache fixed CVE-2026-48827 in MINA SSHD versions 2.18.0 and 3.0.0-M4 in May 2026 by adding centralized path validation for Git repository resolution.
Apache disclosed CVE-2026-35563, a hostname verification flaw in the LDAP API client affecting versions 2.0.0 through 2.1.7 that can enable server impersonation in a man-in-the-middle scenario.
On the oss-sec mailing list, Apache disclosed CVE-2026-48827 affecting sshd-git versions 2.0.0 through 2.17.1 and 3.0.0-M1 through 3.0.0-M3, and advised upgrading to 2.18.0 or 3.0.0-M4.
Apache credited j0hndo with reporting CVE-2026-48827, a path traversal flaw in the sshd-git bundle that can let SSH-authenticated users access repositories outside the configured Git root.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
aretiq.ai
Open sourcecvefeed.io
Open sourceseclists.org
Open sourceseclists.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.