Sonatype Vulnerabilities and Affected Products
Vulnerabilities associated with Nexus Repository.
Products
Clear product- Nexus Repository18 vulnerabilities
- Nexus Repository 313 vulnerabilities
- Nexus Repository Manager4 vulnerabilities
- IQ Server1 vulnerability
- nexus_repository_manager1 vulnerability
- org.sonatype.nexus.common.components:nexus-security1 vulnerability
- org.sonatype.nexus:nexus-security1 vulnerability
- org.sonatype.security:security-system1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-17593HIGH | Nexus Repository - Arbitrary Class Instantiation via Unsafe Realm ConfigurationAn account holding the nexus:settings:update permission in Nexus Repository 3 (or the equivalent nexus:settings permission in the legacy Nexus Repository 2) could submit arbitrary values as realm identifiers through an internal configuration API that did not validate them against the set of registered realms. Because unrecognized entries were persisted and re-evaluated on every realm load via a legacy code path, this could result in unintended code executing inside the Nexus Repository process, … CWE-470Aug 7, 2026 | CVSS7.2v4.0 | EPSS0.308% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-7494MEDIUM | Nexus Repository - SSRF in SSL Certificate RetrievalNexus Repository 3 is vulnerable to Server-Side Request Forgery (SSRF) via the SSL Certificate Retrieval endpoint. A user holding the nexus:ssl-truststore:read permission could cause the server to initiate outbound connections to internal or otherwise restricted network hosts. This issue affects Nexus Repository 3.0.0 through versions prior to 3.94.0. CWE-918Jul 14, 2026 | CVSS5.3v4.0 | EPSS0.146% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-10748HIGH | Nexus Repository 3 - Remote Code Execution via License DeserializationAn authenticated user with the nx-licensing-create privilege can upload a specially crafted license file to execute arbitrary operating system commands as the Nexus process user in Sonatype Nexus Repository 3 versions before 3.92.0. CWE-502Jun 16, 2026 | CVSS8.6v4.0 | EPSS0.296% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-7308MEDIUM | Nexus Repository 3 - Stored Cross-Site Scripting (XSS) via HTML Browse PageAn authenticated user with upload permission to a hosted repository can store content that causes arbitrary JavaScript to execute in the browser of any user who browses that repository directory via the HTML index page in Sonatype Nexus Repository versions 3.6.0 through versions before 3.92.0. This could allow the attacker to perform actions in the context of the victim's session. CWE-79May 11, 2026 | CVSS5.1v4.0 | EPSS0.266% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-3048MEDIUM | Nexus Repository 3 - Improper LDAP Referral HandlingAn authenticated administrator who configures or tests LDAP connectivity in Sonatype Nexus Repository Manager versions 3.0.0 through 3.91.1 may be able to initiate unintended server-side connections when interacting with a malicious LDAP server. | CVSS5.1v4.0 | EPSS0.257% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-5189CRITICAL | Nexus Repository 3 - Hardcoded Credential in Internal Database ComponentCWE-798: Use of Hard-coded Credentials in Sonatype Nexus Repository Manager versions 3.0.0 through 3.70.5 allows an unauthenticated attacker with network access to gain unauthorized read/write access to the internal database and execute arbitrary OS commands as the Nexus process user. Exploitation requires the non-default nexus.orient.binaryListenerEnabled=true configuration to be enabled. CWE-798Apr 15, 2026 | CVSS9.2v4.0 | EPSS0.461% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-3199CRITICAL | Nexus Repository 3 - Authenticated Remote Code Execution via Task Property InjectionA vulnerability in the task management component of Sonatype Nexus Repository versions 3.22.1 through 3.90.2 allows an authenticated attacker with task creation permissions to execute arbitrary code, bypassing the nexus.scripts.allowCreation security control. CWE-502Apr 8, 2026 | CVSS9.4v4.0 | EPSS0.467% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-3438MEDIUM | Nexus Repository 3 - Reflected Cross-Site Scripting (XSS) in ?describe PagesA reflected cross-site scripting vulnerability exists in Sonatype Nexus Repository versions 3.0.0 through 3.90.2 that allows unauthenticated remote attackers to execute arbitrary JavaScript in a victim's browser through a specially crafted URL. Exploitation requires user interaction. CWE-79Apr 8, 2026 | CVSS5.1v4.0 | EPSS0.465% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-0600MEDIUM | Nexus Repository 3 - Server-Side Request Forgery in Proxy Repository ConfigurationServer-Side Request Forgery (SSRF) vulnerability in Sonatype Nexus Repository 3 versions 3.0.0 and later allows authenticated administrators to configure proxy repositories with URLs that can access unintended network destinations, potentially including cloud metadata services and internal network resources. A workaround configuration is available starting in version 3.88.0, but the product remains vulnerable by default. CWE-918Jan 14, 2026 | CVSS6.2v4.0 | EPSS0.27% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-0601MEDIUM | Nexus Repository 3 - Cross-Site ScriptingA reflected cross-site scripting vulnerability exists in Nexus Repository 3 that allows unauthenticated attackers to execute arbitrary JavaScript in a victim's browser through a specially crafted request requiring user interaction. CWE-79Jan 14, 2026 | CVSS5.1v4.0 | EPSS0.37% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-13488MEDIUM | Nexus Repository 3 - Stored Cross-Site Scripting (XSS)Due to a regression introduced in version 3.83.0, a security header is no longer applied to certain user-uploaded content served from repositories. This may allow an authenticated attacker with repository upload privileges to exploit a stored cross-site scripting (XSS) vulnerability with user context. CWE-79Dec 4, 2025 | CVSS5.1v4.0 | EPSS0.323% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-9868HIGH | Nexus Repository 2 - SSRF Vulnerability in Remote Browser PluginServer-Side Request Forgery (SSRF) in the Remote Browser Plugin in Sonatype Nexus Repository 2.x up to and including 2.15.2 allows unauthenticated remote attackers to exfiltrate proxy repository credentials via crafted HTTP requests. CWE-918Oct 8, 2025 | CVSS8.7v4.0 | EPSS0.462% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-5082HIGH | Nexus Repository 2 - Remote Code ExecutionA Remote Code Execution vulnerability has been discovered in Sonatype Nexus Repository 2. This issue affects Nexus Repository 2 OSS/Pro versions up to and including 2.15.1. | CVSS7.1v4.0 | EPSS1.96% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2024-5083MEDIUM | Nexus Repository 2 - Stored XSSA stored Cross-site Scripting vulnerability has been discovered in Sonatype Nexus Repository 2 This issue affects Nexus Repository 2 OSS/Pro versions up to and including 2.15.1. CWE-79Nov 14, 2024 | CVSS5.1v4.0 | EPSS0.397% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-5764MEDIUM | Nexus Repository 3 - Static hard-coded encryption passphrase used by defaultUse of Hard-coded Credentials vulnerability in Sonatype Nexus Repository has been discovered in the code responsible for encrypting any secrets stored in the Nexus Repository configuration database (SMTP or HTTP proxy credentials, user tokens, tokens, among others). The affected versions relied on a static hard-coded encryption passphrase. While it was possible for an administrator to define an alternate encryption passphrase, it could only be done at first boot and not updated. This issue affe… CWE-798Oct 23, 2024 | CVSS5.9v4.0 | EPSS0.392% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-4956HIGH | Nexus Repository 3 - Path TraversalPath Traversal in Sonatype Nexus Repository 3 allows an unauthenticated attacker to read system files. Fixed in version 3.68.1. | CVSS7.5v3.1 | EPSS18.2% | PoCs17 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2020-10199HIGH | Nexus Repository Manager 3 - Remote Code ExecutionSonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2). | CVSS8.8v3.1 | EPSS99.1% | PoCs10 | SignalsListed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2019-7238CRITICAL | Sonatype Nexus Repository Manager Incorrect Access Control VulnerabilitySonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control. Mar 21, 20191 related artifact | CVSS9.8v3.1 | EPSS76.5% | PoCs6 | SignalsListed in CISA KEVNo known ransomware use1 Nuclei template | STIX |