CVE-2026-7494
MEDIUMNexus Repository - SSRF in SSL Certificate Retrieval
Title source: cnaDescription
Nexus Repository 3 is vulnerable to Server-Side Request Forgery (SSRF) via the SSL Certificate Retrieval endpoint. A user holding the nexus:ssl-truststore:read permission could cause the server to initiate outbound connections to internal or otherwise restricted network hosts. This issue affects Nexus Repository 3.0.0 through versions prior to 3.94.0.
References (2)
Core 2
Core References
Vendor Advisory vendor-advisory
https://support.sonatype.com/hc/en-us/articles/53126069518227
Scores
CVSS v4
5.3
EPSS
0.0015
EPSS Percentile
4.3%
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-918
Status
published
Products (1)
Sonatype/Nexus Repository
3.0.0 - 3.94.0
Published
Jul 14, 2026
Tracked Since
Jul 14, 2026