VYPR

Nexus Repository

by Sonatype

CVEs (27)

  • CVE-2026-17603HigAug 7, 2026
    risk 0.57cvss 8.8epss 0.00

    Nexus Repository 3 did not sufficiently restrict which HikariCP connection-pool properties could be set through the DataStore configuration API. A user holding the nx-datastores-update permission could set the connectionInitSql property to execute arbitrary SQL against the…

  • CVE-2026-17600HigAug 7, 2026
    risk 0.57cvss 8.8epss 0.00

    Sonatype Nexus Repository 3 did not immediately terminate a user's active login session or revoke their cached permissions when that user's account was deleted, deactivated, or had its password changed. A user whose account was already logged in at the time of one of these…

  • CVE-2026-3329HigJun 11, 2026
    risk 0.57cvss —epss 0.01

    A remote unauthenticated attacker may be able to conduct credential-guessing attacks against user accounts in Sonatype Nexus Repository via authentication endpoints.

  • CVE-2026-3199HigApr 8, 2026
    risk 0.57cvss 8.8epss 0.01

    A vulnerability in the task management component of Sonatype Nexus Repository versions 3.22.1 through 3.90.2 allows an authenticated attacker with task creation permissions to execute arbitrary code, bypassing the nexus.scripts.allowCreation security control.

  • CVE-2025-9868HigOct 8, 2025
    risk 0.57cvss —epss 0.01

    Server-Side Request Forgery (SSRF) in the Remote Browser Plugin in Sonatype Nexus Repository 2.x up to and including 2.15.2 allows unauthenticated remote attackers to exfiltrate proxy repository credentials via crafted HTTP requests.

  • CVE-2021-40143HigSep 7, 2021
    risk 0.53cvss 8.2epss 0.02

    Sonatype Nexus Repository 3.x through 3.33.1-01 is vulnerable to an HTTP header injection. By sending a crafted HTTP request, a remote attacker may disclose sensitive information or request external resources from a vulnerable instance.

  • CVE-2026-17601HigAug 7, 2026
    risk 0.47cvss 7.2epss 0.00

    A user holding a permission to update privilege definitions could modify a wildcard privilege already assigned to their own role to grant broader permissions than they were authorized to hold, including full administrative access, without any additional authorization check or…

  • CVE-2026-17599HigAug 7, 2026
    risk 0.47cvss 7.2epss 0.00

    Nexus Repository 3 contained an endpoint used to change the administrator account password during initial onboarding. This endpoint did not verify that onboarding was still in progress before allowing the password change, relying instead on the presence of a local onboarding…

  • CVE-2026-17593HigAug 7, 2026
    risk 0.47cvss 7.2epss 0.01

    An account holding the nexus:settings:update permission in Nexus Repository 3 (or the equivalent nexus:settings permission in the legacy Nexus Repository 2) could submit arbitrary values as realm identifiers through an internal configuration API that did not validate them…

  • CVE-2026-14644HigAug 7, 2026
    risk 0.47cvss 7.2epss 0.00

    Nexus Repository 3 contained a privilege escalation vulnerability in the REST privileges API. An authenticated user with permission to manage privileges could, under certain role configurations, escalate their own access to full administrator by exploiting a type-confusion flaw…

  • CVE-2026-77125HigSep 2, 2026
    risk 0.46cvss 7.1epss 0.00

    A vulnerability was identified in Sonatype Nexus Repository 3 in which two blobstore group management REST API endpoints did not correctly enforce the intended authorization check. A user granted only the nexus:blobstores:create permission could invoke these endpoints to convert…

  • CVE-2024-5082HigNov 14, 2024
    risk 0.46cvss —epss 0.03

    A Remote Code Execution vulnerability has been discovered in Sonatype Nexus Repository 2.  This issue affects Nexus Repository 2 OSS/Pro versions up to and including 2.15.1.

  • CVE-2026-77123MedSep 2, 2026
    risk 0.42cvss 6.5epss 0.00

    Nexus Repository 3 contains a sensitive information disclosure vulnerability in the capability read API. An account holding the nexus:capabilities:read privilege can retrieve the plaintext shared secret configured on a webhook capability, which is intended to be masked from all…

  • CVE-2026-77121MedSep 2, 2026
    risk 0.42cvss 6.5epss 0.00

    A user account with permission to deploy artifacts to a hosted Maven repository could upload a POM file containing an oversized metadata field. This causes future attempts to list or browse that repository's components to permanently fail until an administrator repairs the…

  • CVE-2024-5764MedOct 23, 2024
    risk 0.42cvss 6.5epss 0.00

    Use of Hard-coded Credentials vulnerability in Sonatype Nexus Repository has been discovered in the code responsible for encrypting any secrets stored in the Nexus Repository configuration database (SMTP or HTTP proxy credentials, user tokens, tokens, among others). The affected…

  • CVE-2026-17596MedAug 7, 2026
    risk 0.40cvss 6.1epss 0.00

    Nexus Repository 3 was found to be vulnerable to stored cross-site scripting (XSS). A user with the nexus:blobstores:create or nexus:blobstores:update permission could set a blob store name containing malicious script content, which would later execute in the browser of another…

  • CVE-2026-3438MedApr 8, 2026
    risk 0.40cvss 6.1epss 0.01

    A reflected cross-site scripting vulnerability exists in Sonatype Nexus Repository versions 3.0.0 through 3.90.2 that allows unauthenticated remote attackers to execute arbitrary JavaScript in a victim's browser through a specially crafted URL. Exploitation requires user…

  • CVE-2026-14645MedJul 14, 2026
    risk 0.36cvss 5.5epss 0.00

    Nexus Repository 3 does not validate the destination of the "Webhook: Global" capability's configured URL before making an outbound HTTP request, allowing a user holding the Capability Administration permission to cause the server to send requests to internal network locations…

  • CVE-2026-7308MedMay 11, 2026
    risk 0.35cvss 5.4epss 0.00

    An authenticated user with upload permission to a hosted repository can store content that causes arbitrary JavaScript to execute in the browser of any user who browses that repository directory via the HTML index page in Sonatype Nexus Repository versions 3.6.0 through versions…

  • CVE-2026-7494MedJul 14, 2026
    risk 0.33cvss 5.0epss 0.00

    Nexus Repository 3 is vulnerable to Server-Side Request Forgery (SSRF) via the SSL Certificate Retrieval endpoint. A user holding the nexus:ssl-truststore:read permission could cause the server to initiate outbound connections to internal or otherwise restricted network hosts.…

Page 1 of 2

VYPR — Vulnerability Intelligence