Unrated severityNVD Advisory· Published Jul 14, 2026· Updated Jul 15, 2026
Nexus Repository 3 - Server-Side Request Forgery (SSRF) via HTTP Redirect
CVE-2026-14646
Description
Nexus Repository 3 did not apply its existing Server-Side Request Forgery (SSRF) protections to HTTP redirect targets returned by proxy repository upstream servers. Any user with read access to a proxy repository backed by an attacker-controlled or compromised upstream server — including an anonymous user, if anonymous access is enabled — could receive a response from an internal network address or cloud metadata endpoint as repository content, potentially exposing sensitive information such as cloud IAM credentials.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.