VYPR

Nexus Repository Manager 3

by Sonatype

CVEs (20)

  • CVE-2026-5189CriApr 15, 2026
    risk 0.60cvss epss 0.00

    CWE-798: Use of Hard-coded Credentials in Sonatype Nexus Repository Manager versions 3.0.0 through 3.70.5 allows an unauthenticated attacker with network access to gain unauthorized read/write access to the internal database and execute arbitrary OS commands as the Nexus process…

  • CVE-2026-17601HigAug 7, 2026
    risk 0.58cvss epss

    A user holding a permission to update privilege definitions could modify a wildcard privilege already assigned to their own role to grant broader permissions than they were authorized to hold, including full administrative access, without any additional authorization check or…

  • CVE-2026-17603HigAug 7, 2026
    risk 0.57cvss epss

    Nexus Repository 3 did not sufficiently restrict which HikariCP connection-pool properties could be set through the DataStore configuration API. A user holding the nx-datastores-update permission could set the connectionInitSql property to execute arbitrary SQL against the…

  • CVE-2020-15871HigJul 31, 2020
    risk 0.57cvss 8.8epss 0.02

    Sonatype Nexus Repository Manager OSS/Pro version before 3.25.1 allows Remote Code Execution.

  • CVE-2020-11753HigApr 20, 2020
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in Sonatype Nexus Repository Manager in versions 3.21.1 and 3.22.0. It is possible for a user with appropriate privileges to create, modify, and execute scripting tasks without use of the UI or API. NOTE: in 3.22.0, scripting is disabled by default…

  • CVE-2026-10748HigJun 16, 2026
    risk 0.56cvss epss 0.00

    An authenticated user with the nx-licensing-create privilege can upload a specially crafted license file to execute arbitrary operating system commands as the Nexus process user in Sonatype Nexus Repository 3 versions before 3.92.0.

  • CVE-2026-17594HigAug 7, 2026
    risk 0.53cvss epss

    Nexus Repository 3 CE/Pro versions 3.0.0 through 3.94.x contain an incorrect authorization vulnerability (CWE-863) in the repository-creation user interface. An individual user account holding a delegated repository-admin privilege scoped to a specific repository format could…

  • CVE-2021-40143HigSep 7, 2021
    risk 0.53cvss 8.2epss 0.02

    Sonatype Nexus Repository 3.x through 3.33.1-01 is vulnerable to an HTTP header injection. By sending a crafted HTTP request, a remote attacker may disclose sensitive information or request external resources from a vulnerable instance.

  • CVE-2026-17593HigAug 7, 2026
    risk 0.47cvss epss

    An account holding the nexus:settings:update permission in Nexus Repository 3 (or the equivalent nexus:settings permission in the legacy Nexus Repository 2) could submit arbitrary values as realm identifiers through an internal configuration API that did not validate them…

  • CVE-2026-17599MedAug 7, 2026
    risk 0.45cvss epss

    Nexus Repository 3 contained an endpoint used to change the administrator account password during initial onboarding. This endpoint did not verify that onboarding was still in progress before allowing the password change, relying instead on the presence of a local onboarding…

  • CVE-2020-15870MedJul 31, 2020
    risk 0.40cvss 6.1epss 0.01

    Sonatype Nexus Repository Manager OSS/Pro versions before 3.25.1 allow XSS (Issue 2 of 2).

  • CVE-2020-15869MedJul 31, 2020
    risk 0.35cvss 5.4epss 0.01

    Sonatype Nexus Repository Manager OSS/Pro versions before 3.25.1 allow XSS (issue 1 of 2).

  • CVE-2026-17598MedAug 7, 2026
    risk 0.34cvss epss

    Sonatype Nexus Repository 3 did not properly filter internal configuration keys from user-supplied task properties when creating or updating a scheduled task through the administrative UI. An account holding permission to create at least one scheduled task type could supply a…

  • CVE-2026-17597MedAug 7, 2026
    risk 0.33cvss epss

    Nexus Repository 3 contains a Server-Side Request Forgery (SSRF) vulnerability in the email configuration verification feature. A user holding the nexus:settings:update permission could submit arbitrary host and port values to the email test/verification endpoint, causing the…

  • CVE-2026-3048MedMay 11, 2026
    risk 0.33cvss epss 0.00

    An authenticated administrator who configures or tests LDAP connectivity in Sonatype Nexus Repository Manager versions 3.0.0 through 3.91.1 may be able to initiate unintended server-side connections when interacting with a malicious LDAP server.

  • CVE-2026-10741MedJun 17, 2026
    risk 0.32cvss 4.9epss 0.00

    Sonatype Nexus Repository Manager before 3.93.0 contains an authorization vulnerability in the proxy repository configuration that allows a delegated repository administrator to disclose stored upstream proxy credentials.

  • CVE-2021-29158MedApr 23, 2021
    risk 0.32cvss 4.9epss 0.01

    Sonatype Nexus Repository Manager 3 Pro up to and including 3.30.0 has Incorrect Access Control.

  • CVE-2026-14645MedJul 14, 2026
    risk 0.00cvss epss 0.00

    Nexus Repository 3 does not validate the destination of the "Webhook: Global" capability's configured URL before making an outbound HTTP request, allowing a user holding the Capability Administration permission to cause the server to send requests to internal network locations…

  • CVE-2026-14504HigJul 14, 2026
    risk 0.00cvss epss 0.00

    An authorization bypass in Nexus Repository 3's component upload API allowed a user with only read/browse privileges on a Swift, Terraform, or Conda hosted repository to upload arbitrary artifacts, bypassing the intended write-permission check.

  • CVE-2026-11403HigJul 14, 2026
    risk 0.00cvss epss 0.00

    A vulnerability in Sonatype Nexus Repository Manager's format-specific API key generation may allow a remote attacker to gain unauthorized access to repository operations as a targeted user. A format-specific API key realm (NuGet API Key, Docker Bearer Token, or npm Bearer…