Sonatype Nexus Repository
5 known vulnerabilities in Sonatype Nexus Repository, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-77125 CVSS 7.1 high A vulnerability was identified in Sonatype Nexus Repository 3 in which two blobstore group management REST API endpoints did not correctly…
- CVE-2026-77124 CVSS 7.5 high In affected versions of Nexus Repository 3, the script execution endpoint (POST /service/rest/v1/script/{name}/run) did not verify whether…
- CVE-2026-77123 CVSS 6.0 medium Nexus Repository 3 contains a sensitive information disclosure vulnerability in the capability read API. An account holding the…
- CVE-2026-77122 CVSS 5.3 medium An authorization flaw in the REST API repository details endpoint (GET /service/rest/v1/repositories/{repositoryName}) in Sonatype Nexus…
- CVE-2026-77121 CVSS 5.3 medium A user account with permission to deploy artifacts to a hosted Maven repository could upload a POM file containing an oversized metadata…