Unrated severityNVD Advisory· Published Jul 14, 2026· Updated Jul 14, 2026
Nexus Repository - SSRF in SSL Certificate Retrieval
CVE-2026-7494
Description
Nexus Repository 3 is vulnerable to Server-Side Request Forgery (SSRF) via the SSL Certificate Retrieval endpoint. A user holding the nexus:ssl-truststore:read permission could cause the server to initiate outbound connections to internal or otherwise restricted network hosts. This issue affects Nexus Repository 3.0.0 through versions prior to 3.94.0.
Affected products
1- Range: 3.0.0 - <3.94.0
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.