High severity8.2NVD Advisory· Published Sep 7, 2021· Updated Jun 17, 2026
CVE-2021-40143
CVE-2021-40143
Description
Sonatype Nexus Repository 3.x through 3.33.1-01 is vulnerable to an HTTP header injection. By sending a crafted HTTP request, a remote attacker may disclose sensitive information or request external resources from a vulnerable instance.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.sonatype.nexus:nexus-repositoryMaven | >= 3.0.0, < 3.34.0-01 | 3.34.0-01 |
Affected products
3- cpe:2.3:a:sonatype:nexus_repository_manager_3:*:*:*:*:*:*:*:*Range: >=3.0.0,<3.34.0
- Sonatype/Nexus Repositorydescription
Patches
Vulnerability mechanics
References
5- support.sonatype.com/hc/en-us/articles/4405941762579nvdPatchVendor AdvisoryWEB
- github.com/advisories/GHSA-f34x-8pf6-qc9cghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-40143ghsaADVISORY
- help.sonatype.com/repomanager3/release-notes/2021-release-notesghsaWEB
- issues.sonatype.org/secure/ReleaseNote.jspanvdNot ApplicableWEB
News mentions
0No linked articles in our index yet.