Nexus Repository 2 is end of life

Sonatype has sunset Nexus Repository 2. Its own advisory says Nexus Repository Manager 2 does not receive security patches. Since the sunset Sonatype has published two vulnerabilities that affect Nexus Repository 2, and neither has a Nexus 2 fix: Sonatype says it will not release one for CVE-2025-9868, and its advisory for CVE-2026-17593 names a fix only in Nexus Repository 3.95.0. If a server reports a 2.x version, this page covers what Sonatype says happened, which CVEs apply, what moving to Nexus Repository 3 involves, and the managed alternative.

Every date, version and CVE below links to the Sonatype or NVD page that states it. Read on October 6, 2026. This page is not a scan of any server.

What Sonatype says happened

Sonatype's pages date the end in two steps, June 30, 2024 and June 30, 2025, and the wording differs from page to page. Each date below is credited to the page that states it.

  1. Sonatype's Nexus Repository 2 page says that as of this date Nexus Repository Manager 2 has reached End-of-Life (EOL) status, and recommends upgrading to Nexus Repository 3.

    Source: Sonatype: Nexus Repository Manager 2 is Now End-of-Life

  2. Sonatype's advisory for CVE-2024-5082, a remote code execution flaw, names Nexus Repository Manager 2.15.2 as the fix and describes Nexus 2 as under Extended Maintenance.

    Source: Sonatype advisory for CVE-2024-5082

  3. Sonatype officially sunset Nexus Repository 2, according to its Sunsetting Information page. Its version status page says that from this date Sonatype no longer releases any additional features or bug fixes for Nexus Repository 2.

    Source: Sonatype Nexus Repository 2 Sunsetting Information; Sonatype Nexus Repository 2 Version Status

  4. Sonatype's advisory for CVE-2025-9868 says Nexus Repository Manager 2 does not receive security patches and that Sonatype will not release a fix for that issue.

    Source: Sonatype advisory for CVE-2025-9868

In Sonatype's lifecycle, a sunsetted product gets no additional features or bug fixes, and support gives best-effort guidance to help customers adopt alternatives. Sonatype's lifecycle definitions.

CVEs published after the sunset (2)

These are the CVEs published after June 30, 2025 that NVD or Sonatype's advisory name as affecting Nexus Repository 2. A vulnerability is not listed when Sonatype's advisory and NVD's analysis name Nexus Repository 3 only. Its CVE record may also list Maven packages with version ranges that start in the 2.x series; we have not read those as naming Nexus Repository 2. Earlier Nexus 2 CVEs are in Sonatype's security advisories.

CVE-2025-9868 ·

Server-side request forgery in the Remote Browser Plugin

An unauthenticated attacker can use the Remote Browser Plugin to send arbitrary HTTP GET requests to servers the attacker controls. If a proxy repository is configured with authentication, its credentials may be leaked.

Affected
All Nexus Repository Manager 2.x OSS and Pro versions. The CVE record lists 2.0.0 through 2.15.2.
Fix for Nexus 2
None. The advisory says Sonatype will not release a fix.
Severity
CVSS 4.0 score 8.7, High, rated by Sonatype. NVD has not given it a score of its own.
NVD status
Deferred

Sonatype's advisory suggests removing the Remote Browser Plugin, which it says is enabled by default, and placing the server behind a restrictive reverse proxy or firewall that limits outbound connections.

Sources: NVD record for CVE-2025-9868; Sonatype advisory for CVE-2025-9868.

CVE-2026-17593 ·

Arbitrary class instantiation through unsafe realm configuration

An account holding the nexus:settings:update permission in Nexus Repository 3, or the equivalent nexus:settings permission in Nexus Repository 2, could submit arbitrary values as realm identifiers, which an internal API did not validate against the registered realms. The CVE record says this could result in unintended code executing inside the Nexus Repository process, and in some cases a persistent authentication lockout.

Affected
Sonatype's advisory lists all versions from 2.8.0 up to and including 3.94.x.
Fix for Nexus 2
The advisory names a fix only in Nexus Repository 3.95.0. It names none for Nexus 2.
Severity
CVSS 3.1 score 7.2, High, rated by NVD. Sonatype rates it 7.2 High on CVSS 4.0.
NVD status
Analyzed

Sources: NVD record for CVE-2026-17593; Sonatype advisory for CVE-2026-17593.

What moving to Nexus Repository 3 involves

Everything in this section is from Sonatype's documentation, linked on each point. Its pages change, so read the current ones before you plan.

  • Nexus Repository 3 is a complete redesign

    Sonatype describes Nexus Repository 3 as a complete redesign that does not include legacy code from Nexus Repository 2, with a different storage model. It says upgrading requires completely transforming the repository metadata and artifact storage model.

    Source: Sonatype: Upgrade from Nexus Repository 2

  • The Upgrade Wizard stops at Nexus 3.95.0

    The built-in Upgrade Wizard is in Nexus Repository 3 versions up to and including 3.95.0 and is not in 3.96.0 and later. Sonatype says to install a new Nexus Repository 3 instance on 3.95.0 or earlier, run the wizard, and then upgrade that instance to the latest supported release.

    Source: Sonatype: Upgrade from Nexus Repository 2; Sonatype: Upgrade Wizard

  • The wizard has conditions

    The Nexus Repository 3 instance must be new and unused in production, and Sonatype calls the process destructive to most of that instance's configuration. The wizard is not supported with a highly available Nexus Repository 3 deployment or with Nexus Repository Cloud. If you use Pro, the license must be installed in both instances. Repository IDs that differ only by case are not accepted, and roles cannot carry the nx2 prefix.

    Source: Sonatype: Upgrade Wizard; Sonatype: Upgrade from Nexus Repository 2

  • Scripts and plugins are rewritten

    Scripts written against the Nexus Repository 2 APIs do not work with Nexus Repository 3, and plugins need to be rewritten against the Nexus Repository 3 API.

    Source: Sonatype: Upgrade from Nexus Repository 2

  • You choose a database

    Nexus Repository 3 offers an external PostgreSQL database, which Sonatype prefers, and an embedded H2 database, which it recommends only for small workloads, up to 200,000 requests a day and 100,000 components. The legacy OrientDB database is in extended maintenance, and Sonatype says deployments must migrate off it. Its upgrade paths page calls 3.70.x the last version line that supports OrientDB. For Community Edition, the wizard page describes upgrading to 3.76.0 with H2 and then moving to PostgreSQL on the latest release, and it gives a different path for Pro: read it before you pick a version.

    Source: Sonatype: Nexus Repository Database; Sonatype: Nexus Repository Upgrade Paths; Sonatype: Upgrade Wizard

  • Formats, access control and staging change

    Sonatype says Nexus Repository 3 supports more formats natively, and that some, such as Docker and raw, are not available in Nexus Repository 2. Repository targets are replaced by content selectors. Staging is based on component tagging and REST APIs instead of the Maven-only staging suite in Nexus Repository 2. Nexus Repository 3 can also support legacy Nexus Repository 2 style repository URLs to ease the move for automation and CI tools.

    Source: Sonatype: Nexus Repository Manager 2 is Now End-of-Life

Another way out: managed hosting

Self-hosting Nexus Repository 3 means running and patching a server again. CloudRepo is a managed artifact repository for Maven, npm, Python (PyPI) and Docker/OCI, with Raw (HTTP) repositories too, so there is no server to maintain. It works with the standard Maven, npm, pip and Docker clients you already use. Plans start at $199 a month on annual billing, and the plans are on the pricing page.

Compare CloudRepo with Nexus or read the Nexus to CloudRepo migration guide.

About this page and CloudRepo

CloudRepo is a managed artifact repository, so there is no Artifactory or Nexus server for you to patch. In over 10 years of operation, CloudRepo has experienced no known security breaches. This page is not a scan of your server: the data is NVD's and the vendor's, linked on every row, pulled on October 6, 2026.