Sonatype Nexus Repository 3.16.0: known vulnerabilities
45 known CVEs affect Sonatype Nexus Repository 3.16.0: 40 by NVD's exact CPE match, and 5 more that Sonatype's advisories list and NVD has not analyzed.
NVD's count evaluates NVD's published version ranges against this version; those ranges do not carry Sonatype's per-branch fixes, so the NVD column can read the same on either side of a fix that Sonatype names. Where NVD has not analyzed a record, the row reads "no NVD data", not "no".
- Known CVEs
- 45
- Critical 2 High 15 Medium 28
- 2 critical, 15 high, 28 medium
- Released
- Not published
- Release date not published by the vendor; Sonatype lists 3.16.0 only in its CVE records.
- End of life
- Sonatype status: Not listed. This version predates Sonatype's versions status page.
- Behind latest
- Latest is 3.96.2 (released September 18, 2026); days behind not computable, release date not published by the vendor.
Sonatype's policy: Sonatype Nexus Repository releases are considered generally available and fully supported for a term of 1 year after the version's release date. Sonatype provides extended maintenance for each Sonatype Nexus Repository version for an additional 6 months before that version is considered sunset.
Sources: NVD (exact CPE match and the published configurations), the CVE Program record (the vendor's CNA entry with its affected and fixed versions), Sonatype's security advisories, release notes and end-of-life page. Pulled September 18, 2026. Every CVE row links to its NVD record and to the vendor's advisory.
CVEs that affect 3.16.0 (45)
Two verdicts per row, side by side: what NVD's exact CPE match says, and what Sonatype's own CVE record says. A CVE counts when either source says affected. Open a row's sources for the raw ranges.
| CVE | Severity | Affected per NVD | Affected per Sonatype | Fix on your branch |
|---|---|---|---|---|
| CVE-2019-9629 published July 8, 2019 Sonatype Nexus Repository Manager before 3.17.0 establishes a default administrator user with weak defaults (fixed credentials). | Critical9.8 CVSS 3.0 9.8, rated by NVD | yes | no Sonatype CNA range | No Sonatype CNA range for this CVE (assigned by MITRE). NVD's range ends before 3.17.0; see Sonatype's advisory. Latest: 3.96.2. |
Sources for CVE-2019-9629 and 3.16.0 Hide sources
| ||||
| CVE-2026-5189 published April 15, 2026 CWE-798: Use of Hard-coded Credentials in Sonatype Nexus Repository Manager versions 3.0.0 through 3.70.5 allows an unauthenticated attacker with network access to gain unauthorized read/write access to the internal database and execute arbitrary OS commands as the Nexus process user. Exploitation requires the non-default nexus.orient.binaryListenerEnabled=true configuration to be enabled. | Critical9.8 CVSS 3.1 9.8, rated by NVD | yes | yes | No fix on your branch; the nearest fix is 3.71.0. Latest: 3.96.2. |
Sources for CVE-2026-5189 and 3.16.0 Hide sources
| ||||
| CVE-2020-10199 published April 1, 2020 Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2). | High8.8 CVSS 3.1 8.8, rated by NVD | yes | yes | No fix on your branch; the nearest fix is 3.21.2. Latest: 3.96.2. |
Sources for CVE-2020-10199 and 3.16.0 Hide sources
| ||||
| CVE-2020-11444 published April 2, 2020 Sonatype Nexus Repository Manager 3.x up to and including 3.21.2 has Incorrect Access Control. | High8.8 CVSS 3.1 8.8, rated by NVD | yes | yes | No fix on your branch; the nearest fix is 3.22.0. Latest: 3.96.2. |
Sources for CVE-2020-11444 and 3.16.0 Hide sources
| ||||
| CVE-2020-15871 published July 31, 2020 Sonatype Nexus Repository Manager OSS/Pro version before 3.25.1 allows Remote Code Execution. | High8.8 CVSS 3.1 8.8, rated by NVD | yes | no Sonatype CNA range | No Sonatype CNA range for this CVE (assigned by MITRE). NVD's range ends before 3.25.1; see Sonatype's advisory. Latest: 3.96.2. |
Sources for CVE-2020-15871 and 3.16.0 Hide sources
| ||||
| CVE-2026-11403 published July 14, 2026 A vulnerability in Sonatype Nexus Repository Manager's format-specific API key generation may allow a remote attacker to gain unauthorized access to repository operations as a targeted user. A format-specific API key realm (NuGet API Key, Docker Bearer Token, or npm Bearer Token) must be enabled and the targeted user must have an active API key for this vulnerability to be exploitable. | High8.7 CVSS 4.0 8.7, rated by Sonatype (CNA) | yes | yes | No fix on your branch; the nearest fix is 3.93.0. Latest: 3.96.2. |
Sources for CVE-2026-11403 and 3.16.0 Hide sources
| ||||
| CVE-2026-17600 published August 7, 2026 Sonatype Nexus Repository 3 did not immediately terminate a user's active login session or revoke their cached permissions when that user's account was deleted, deactivated, or had its password changed. A user whose account was already logged in at the time of one of these actions could continue using their existing session to interact with the repository as though the account were still active, until that session independently expired. Depending on the permissions previously held, this could allow continued unauthorized access to read, modify, or delete repository content after access was intended to be revoked. | High8.7 CVSS 4.0 8.7, rated by Sonatype (CNA) | yes | yes | No fix on your branch; the nearest fix is 3.95.0. Latest: 3.96.2. |
Sources for CVE-2026-17600 and 3.16.0 Hide sources
| ||||
| CVE-2026-10748 published June 16, 2026 An authenticated user with the nx-licensing-create privilege can upload a specially crafted license file to execute arbitrary operating system commands as the Nexus process user in Sonatype Nexus Repository 3 versions before 3.92.0. | High8.6 CVSS 4.0 8.6, rated by Sonatype (CNA) | yes | yes | No fix on your branch; the nearest fix is 3.92.0. Latest: 3.96.2. |
Sources for CVE-2026-10748 and 3.16.0 Hide sources
| ||||
| CVE-2021-40143 published September 7, 2021 Sonatype Nexus Repository 3.x through 3.33.1-01 is vulnerable to an HTTP header injection. By sending a crafted HTTP request, a remote attacker may disclose sensitive information or request external resources from a vulnerable instance. | High8.2 CVSS 3.1 8.2, rated by NVD | yes | yes | No fix on your branch; the nearest fix is 3.34.0. Latest: 3.96.2. |
Sources for CVE-2021-40143 and 3.16.0 Hide sources
| ||||
| CVE-2026-17594 published August 7, 2026 Nexus Repository 3 CE/Pro versions 3.0.0 through 3.94.x contain an incorrect authorization vulnerability (CWE-863) in the repository-creation user interface. An individual user account holding a delegated repository-admin privilege scoped to a specific repository format could create a repository of a different, unauthorized format, because authorization was checked against one request field while a separate, attacker-controlled field determined the repository format actually created. This does not affect the anonymous user, which cannot hold this privilege by default. Fixed in version 3.95.0. | High8.2 CVSS 4.0 8.2, rated by Sonatype (CNA) | yes | yes | No fix on your branch; the nearest fix is 3.95.0. Latest: 3.96.2. |
Sources for CVE-2026-17594 and 3.16.0 Hide sources
| ||||
| CVE-2019-9630 published July 8, 2019 Sonatype Nexus Repository Manager before 3.17.0 has a weak default of giving any unauthenticated user read permissions on the repository files and images. | High7.5 CVSS 3.0 7.5, rated by NVD | yes | no Sonatype CNA range | No Sonatype CNA range for this CVE (assigned by MITRE). NVD's range ends before 3.17.0; see Sonatype's advisory. Latest: 3.96.2. |
Sources for CVE-2019-9630 and 3.16.0 Hide sources
| ||||
| CVE-2020-15868 published August 12, 2020 Sonatype Nexus Repository Manager OSS/Pro before 3.26.0 has Incorrect Access Control. | High7.5 CVSS 3.1 7.5, rated by NVD | yes | no Sonatype CNA range | No Sonatype CNA range for this CVE (assigned by MITRE). NVD's range ends before 3.26.0; see Sonatype's advisory. Latest: 3.96.2. |
Sources for CVE-2020-15868 and 3.16.0 Hide sources
| ||||
| CVE-2024-4956 published May 16, 2024 Path Traversal in Sonatype Nexus Repository 3 allows an unauthenticated attacker to read system files. Fixed in version 3.68.1. | High7.5 CVSS 3.1 7.5, rated by Sonatype (CNA) | no NVD data | yes | No fix on your branch; the nearest fix is 3.68.1. Latest: 3.96.2. |
Sources for CVE-2024-4956 and 3.16.0 Hide sources
| ||||
| CVE-2026-3329 published June 11, 2026 A remote unauthenticated attacker may be able to conduct credential-guessing attacks against user accounts in Sonatype Nexus Repository via authentication endpoints. | High7.5 CVSS 3.1 7.5, rated by NVD | yes | yes | No fix on your branch; the nearest fix is 3.93.0. Latest: 3.96.2. |
Sources for CVE-2026-3329 and 3.16.0 Hide sources
| ||||
| CVE-2019-16530 published October 21, 2019 Sonatype Nexus Repository Manager 2.x before 2.14.15 and 3.x before 3.19, and IQ Server before 72, has remote code execution. | High7.2 CVSS 3.1 7.2, rated by NVD | yes | yes | No fix on your branch; the nearest fix is 3.19.0. Latest: 3.96.2. |
Sources for CVE-2019-16530 and 3.16.0 Hide sources
| ||||
| CVE-2020-10204 published April 1, 2020 Sonatype Nexus Repository before 3.21.2 allows Remote Code Execution. | High7.2 CVSS 3.1 7.2, rated by NVD | yes | no Sonatype CNA range | No Sonatype CNA range for this CVE (assigned by MITRE). NVD's range ends before 3.21.2; see Sonatype's advisory. Latest: 3.96.2. |
Sources for CVE-2020-10204 and 3.16.0 Hide sources
| ||||
| CVE-2026-17593 published August 7, 2026 An account holding the nexus:settings:update permission in Nexus Repository 3 (or the equivalent nexus:settings permission in the legacy Nexus Repository 2) could submit arbitrary values as realm identifiers through an internal configuration API that did not validate them against the set of registered realms. Because unrecognized entries were persisted and re-evaluated on every realm load via a legacy code path, this could result in unintended code executing inside the Nexus Repository process, and in some cases a persistent authentication lockout that was not visible through the administrative UI. | High7.2 CVSS 4.0 7.2, rated by Sonatype (CNA) | yes | yes | No fix on your branch; the nearest fix is 3.95.0. Latest: 3.96.2. |
Sources for CVE-2026-17593 and 3.16.0 Hide sources
| ||||
| CVE-2020-29436 published December 17, 2020 Sonatype Nexus Repository Manager 3.x before 3.29.0 allows a user with admin privileges to configure the system to gain access to content outside of NXRM via an XXE vulnerability. Fixed in version 3.29.0. | Medium6.5 CVSS 3.1 6.5, rated by NVD | yes | no Sonatype CNA range | No Sonatype CNA range for this CVE (assigned by MITRE). NVD's range ends before 3.29.0; see Sonatype's advisory. Latest: 3.96.2. |
Sources for CVE-2020-29436 and 3.16.0 Hide sources
| ||||
| CVE-2024-5764 published October 23, 2024 Use of Hard-coded Credentials vulnerability in Sonatype Nexus Repository has been discovered in the code responsible for encrypting any secrets stored in the Nexus Repository configuration database (SMTP or HTTP proxy credentials, user tokens, tokens, among others). The affected versions relied on a static hard-coded encryption passphrase. While it was possible for an administrator to define an alternate encryption passphrase, it could only be done at first boot and not updated. This issue affects Nexus Repository: from 3.0.0 through 3.72.0. | Medium6.5 CVSS 3.1 6.5, rated by NVD | yes | yes | No fix on your branch; the nearest fix is 3.73.0. Latest: 3.96.2. |
Sources for CVE-2024-5764 and 3.16.0 Hide sources
| ||||
| CVE-2026-17596 published August 7, 2026 Nexus Repository 3 was found to be vulnerable to stored cross-site scripting (XSS). A user with the nexus:blobstores:create or nexus:blobstores:update permission could set a blob store name containing malicious script content, which would later execute in the browser of another user viewing system health-check status. This issue has been fixed in version 3.95.0. | Medium6.3 CVSS 4.0 6.3, rated by Sonatype (CNA) | yes | yes | No fix on your branch; the nearest fix is 3.95.0. Latest: 3.96.2. |
Sources for CVE-2026-17596 and 3.16.0 Hide sources
| ||||
| CVE-2026-0600 published January 14, 2026 Server-Side Request Forgery (SSRF) vulnerability in Sonatype Nexus Repository 3 versions 3.0.0 and later allows authenticated administrators to configure proxy repositories with URLs that can access unintended network destinations, potentially including cloud metadata services and internal network resources. A workaround configuration is available starting in version 3.88.0, but the product remains vulnerable by default. | Medium6.2 CVSS 4.0 6.2, rated by Sonatype (CNA) | no NVD data | yes | No fixed version published. Sonatype names a workaround from Sonatype Nexus Repository 3.88.0 (CE/Pro). Latest: 3.96.2. |
Sources for CVE-2026-0600 and 3.16.0 Hide sources
| ||||
| CVE-2020-15870 published July 31, 2020 Sonatype Nexus Repository Manager OSS/Pro versions before 3.25.1 allow XSS (Issue 2 of 2). | Medium6.1 CVSS 3.1 6.1, rated by NVD | yes | yes | No fix on your branch; the nearest fix is 3.25.1. Latest: 3.96.2. |
Sources for CVE-2020-15870 and 3.16.0 Hide sources
| ||||
| CVE-2026-3438 published April 8, 2026 A reflected cross-site scripting vulnerability exists in Sonatype Nexus Repository versions 3.0.0 through 3.90.2 that allows unauthenticated remote attackers to execute arbitrary JavaScript in a victim's browser through a specially crafted URL. Exploitation requires user interaction. | Medium6.1 CVSS 3.1 6.1, rated by NVD | yes | yes | No fix on your branch; the nearest fix is 3.91.0. Latest: 3.96.2. |
Sources for CVE-2026-3438 and 3.16.0 Hide sources
| ||||
| CVE-2026-77123 published September 2, 2026 Nexus Repository 3 contains a sensitive information disclosure vulnerability in the capability read API. An account holding the nexus:capabilities:read privilege can retrieve the plaintext shared secret configured on a webhook capability, which is intended to be masked from all API responses. This issue affects Nexus Repository 3 versions 3.2.0 through 3.95.x, and is fixed in version 3.96.0. | Medium6.0 CVSS 4.0 6.0, rated by Sonatype (CNA) | yes | yes | No fix on your branch; the nearest fix is 3.96.0. Latest: 3.96.2. |
Sources for CVE-2026-77123 and 3.16.0 Hide sources
| ||||
| CVE-2019-14469 published August 22, 2019 In Nexus Repository Manager before 3.18.0, users with elevated privileges can create stored XSS. | Medium5.4 CVSS 3.0 5.4, rated by NVD | yes | yes | No fix on your branch; the nearest fix is 3.18.0. Latest: 3.96.2. |
Sources for CVE-2019-14469 and 3.16.0 Hide sources
| ||||
| CVE-2020-15869 published July 31, 2020 Sonatype Nexus Repository Manager OSS/Pro versions before 3.25.1 allow XSS (issue 1 of 2). | Medium5.4 CVSS 3.1 5.4, rated by NVD | yes | yes | No fix on your branch; the nearest fix is 3.25.1. Latest: 3.96.2. |
Sources for CVE-2020-15869 and 3.16.0 Hide sources
| ||||
| CVE-2021-37152 published August 10, 2021 Multiple XSS issues exist in Sonatype Nexus Repository Manager 3 before 3.33.0. An authenticated attacker with the ability to add HTML files to a repository could redirect users to Nexus Repository Manager’s pages with code modifications. | Medium5.4 CVSS 3.1 5.4, rated by NVD | yes | yes | No fix on your branch; the nearest fix is 3.33.0. Latest: 3.96.2. |
Sources for CVE-2021-37152 and 3.16.0 Hide sources
| ||||
| CVE-2021-30635 published April 27, 2021 Sonatype Nexus Repository Manager 3.x before 3.30.1 allows a remote attacker to get a list of files and directories that exist in a UI-related folder via directory traversal (no customer-specific data is exposed). | Medium5.3 CVSS 3.1 5.3, rated by NVD | yes | yes | No fix on your branch; the nearest fix is 3.30.1. Latest: 3.96.2. |
Sources for CVE-2021-30635 and 3.16.0 Hide sources
| ||||
| CVE-2026-17595 published August 7, 2026 Nexus Repository 3 did not fully sandbox JEXL expressions used in Content Selectors. An account holding the nexus:selectors:create permission could construct an expression that read Java object properties not intended to be exposed to the expression engine, disclosing internal JVM class metadata such as class and classloader names. This issue does not permit method invocation, object construction, or arbitrary code execution. This has been fixed by restricting property access in the JEXL sandbox to the intended data types. | Medium5.3 CVSS 4.0 5.3, rated by Sonatype (CNA) | yes | yes | No fix on your branch; the nearest fix is 3.95.0. Latest: 3.96.2. |
Sources for CVE-2026-17595 and 3.16.0 Hide sources
| ||||
| CVE-2026-7494 published July 14, 2026 Nexus Repository 3 is vulnerable to Server-Side Request Forgery (SSRF) via the SSL Certificate Retrieval endpoint. A user holding the nexus:ssl-truststore:read permission could cause the server to initiate outbound connections to internal or otherwise restricted network hosts. This issue affects Nexus Repository 3.0.0 through versions prior to 3.94.0. | Medium5.3 CVSS 4.0 5.3, rated by Sonatype (CNA) | no NVD data | yes | No fix on your branch; the nearest fix is 3.94.0. Latest: 3.96.2. |
Sources for CVE-2026-7494 and 3.16.0 Hide sources
| ||||
| CVE-2026-14645 published July 14, 2026 Nexus Repository 3 does not validate the destination of the "Webhook: Global" capability's configured URL before making an outbound HTTP request, allowing a user holding the Capability Administration permission to cause the server to send requests to internal network locations (Server-Side Request Forgery). This permission is granted by role assignment, independent of authentication status, so an unauthenticated user could also trigger this behavior if the anonymous role has been granted the permission. | Medium5.1 CVSS 4.0 5.1, rated by Sonatype (CNA) | no NVD data | yes | No fix on your branch; the nearest fix is 3.94.0. Latest: 3.96.2. |
Sources for CVE-2026-14645 and 3.16.0 Hide sources
| ||||
| CVE-2026-17597 published August 7, 2026 Nexus Repository 3 contains a Server-Side Request Forgery (SSRF) vulnerability in the email configuration verification feature. A user holding the nexus:settings:update permission could submit arbitrary host and port values to the email test/verification endpoint, causing the server to attempt outbound network connections to internal or otherwise restricted network addresses. Differences in the server's response could be used to infer whether internal hosts and ports are reachable. This issue affects Nexus Repository 3 CE/Pro versions up to and including 3.94.1, and is fixed in version 3.95.0. | Medium5.1 CVSS 4.0 5.1, rated by Sonatype (CNA) | yes | yes | No fix on your branch; the nearest fix is 3.95.0. Latest: 3.96.2. |
Sources for CVE-2026-17597 and 3.16.0 Hide sources
| ||||
| CVE-2026-3048 published May 11, 2026 An authenticated administrator who configures or tests LDAP connectivity in Sonatype Nexus Repository Manager versions 3.0.0 through 3.91.1 may be able to initiate unintended server-side connections when interacting with a malicious LDAP server. | Medium5.1 CVSS 4.0 5.1, rated by Sonatype (CNA) | yes | yes | No fix on your branch; the nearest fix is 3.92.0. Latest: 3.96.2. |
Sources for CVE-2026-3048 and 3.16.0 Hide sources
| ||||
| CVE-2026-7308 published May 11, 2026 An authenticated user with upload permission to a hosted repository can store content that causes arbitrary JavaScript to execute in the browser of any user who browses that repository directory via the HTML index page in Sonatype Nexus Repository versions 3.6.0 through versions before 3.92.0. This could allow the attacker to perform actions in the context of the victim's session. | Medium5.1 CVSS 4.0 5.1, rated by Sonatype (CNA) | no NVD data | yes | No fix on your branch; the nearest fix is 3.92.0. Latest: 3.96.2. |
Sources for CVE-2026-7308 and 3.16.0 Hide sources
| ||||
| CVE-2020-11415 published April 27, 2020 An issue was discovered in Sonatype Nexus Repository Manager 2.x before 2.14.17 and 3.x before 3.22.1. Admin users can retrieve the LDAP server system username/password (as configured in nxrm) in cleartext. | Medium4.9 CVSS 3.1 4.9, rated by NVD | yes | no Sonatype CNA range | No Sonatype CNA range for this CVE (assigned by MITRE). NVD's range ends before 3.22.1; see Sonatype's advisory. Latest: 3.96.2. |
Sources for CVE-2020-11415 and 3.16.0 Hide sources
| ||||
| CVE-2020-24622 published August 25, 2020 In Sonatype Nexus Repository 3.26.1, an S3 secret key can be exposed by an admin user. | Medium4.9 CVSS 3.1 4.9, rated by NVD | yes | yes | No fix on your branch; the nearest fix is 3.27.0. Latest: 3.96.2. |
Sources for CVE-2020-24622 and 3.16.0 Hide sources
| ||||
| CVE-2021-29158 published April 23, 2021 Sonatype Nexus Repository Manager 3 Pro up to and including 3.30.0 has Incorrect Access Control. | Medium4.9 CVSS 3.1 4.9, rated by NVD | yes | yes | No fix on your branch; the nearest fix is 3.30.1. Latest: 3.96.2. |
Sources for CVE-2021-29158 and 3.16.0 Hide sources
| ||||
| CVE-2026-10741 published June 17, 2026 Sonatype Nexus Repository Manager before 3.93.0 contains an authorization vulnerability in the proxy repository configuration that allows a delegated repository administrator to disclose stored upstream proxy credentials. | Medium4.9 CVSS 3.1 4.9, rated by NVD | yes | yes | No fix on your branch; the nearest fix is 3.93.0. Latest: 3.96.2. |
Sources for CVE-2026-10741 and 3.16.0 Hide sources
| ||||
| CVE-2026-14646 published July 14, 2026 Nexus Repository 3 did not apply its existing Server-Side Request Forgery (SSRF) protections to HTTP redirect targets returned by proxy repository upstream servers. Any user with read access to a proxy repository backed by an attacker-controlled or compromised upstream server - including an anonymous user, if anonymous access is enabled - could receive a response from an internal network address or cloud metadata endpoint as repository content, potentially exposing sensitive information such as cloud IAM credentials. | Medium4.9 CVSS 4.0 4.9, rated by Sonatype (CNA) | yes | yes | No fix on your branch; the nearest fix is 3.94.0. Latest: 3.96.2. |
Sources for CVE-2026-14646 and 3.16.0 Hide sources
| ||||
| CVE-2020-10203 published April 1, 2020 Sonatype Nexus Repository before 3.21.2 allows XSS. | Medium4.8 CVSS 3.1 4.8, rated by NVD | yes | no Sonatype CNA range | No Sonatype CNA range for this CVE (assigned by MITRE). NVD's range ends before 3.21.2; see Sonatype's advisory. Latest: 3.96.2. |
Sources for CVE-2020-10203 and 3.16.0 Hide sources
| ||||
| CVE-2021-34553 published June 18, 2021 Sonatype Nexus Repository Manager 3.x before 3.31.0 allows a remote authenticated attacker to get a list of blob files and read the content of a blob file (via a GET request) without having been granted access. | Medium4.3 CVSS 3.1 4.3, rated by NVD | yes | yes | No fix on your branch; the nearest fix is 3.31.0. Latest: 3.96.2. |
Sources for CVE-2021-34553 and 3.16.0 Hide sources
| ||||
| CVE-2021-42568 published November 2, 2021 Sonatype Nexus Repository Manager 3.x through 3.35.0 allows attackers to access the SSL Certificates Loading function via a low-privileged account. | Medium4.3 CVSS 3.1 4.3, rated by NVD | yes | no Sonatype CNA range | No Sonatype CNA range for this CVE (assigned by MITRE). NVD's range runs through 3.35.0; see Sonatype's advisory. Latest: 3.96.2. |
Sources for CVE-2021-42568 and 3.16.0 Hide sources
| ||||
| CVE-2021-43293 published November 4, 2021 Sonatype Nexus Repository Manager 3.x before 3.36.0 allows a remote authenticated attacker to potentially perform network enumeration via Server Side Request Forgery (SSRF). | Medium4.3 CVSS 3.1 4.3, rated by NVD | yes | no Sonatype CNA range | No Sonatype CNA range for this CVE (assigned by MITRE). NVD's range runs through 3.35.0; see Sonatype's advisory. Latest: 3.96.2. |
Sources for CVE-2021-43293 and 3.16.0 Hide sources
| ||||
| CVE-2021-43961 published March 17, 2022 Sonatype Nexus Repository Manager 3.36.0 allows HTML Injection. | Medium4.3 CVSS 3.1 4.3, rated by NVD | yes | yes | No fix on your branch; the nearest fix is 3.38.0. Latest: 3.96.2. |
Sources for CVE-2021-43961 and 3.16.0 Hide sources
| ||||
| CVE-2022-27907 published March 30, 2022 Sonatype Nexus Repository Manager 3.x before 3.38.0 allows SSRF. | Medium4.3 CVSS 3.1 4.3, rated by NVD | yes | yes | No fix on your branch; the nearest fix is 3.38.0. Latest: 3.96.2. |
Sources for CVE-2022-27907 and 3.16.0 Hide sources
| ||||
21 other Sonatype Nexus Repository CVEs on record that do not affect 3.16.0
Each of these is fixed at or before 3.16.0 on its branch, or its published range does not include this version. The fix column shows the fix this version already carries.
| CVE | Severity | Affected per NVD | Affected per Sonatype | Fix on your branch |
|---|---|---|---|---|
| CVE-2019-7238 published March 21, 2019 | Critical9.8 CVSS 3.1 9.8, rated by NVD | no | no Sonatype CNA range | No Sonatype CNA range for this CVE (assigned by MITRE); NVD's published range does not include this version. |
Sources for CVE-2019-7238 and 3.16.0 Hide sources
| ||||
| CVE-2026-17601 published August 7, 2026 | High8.9 CVSS 4.0 8.9, rated by Sonatype (CNA) | no | no | This version predates the affected range (from 3.19.0). |
Sources for CVE-2026-17601 and 3.16.0 Hide sources
| ||||
| CVE-2020-11753 published April 20, 2020 | High8.8 CVSS 3.1 8.8, rated by NVD | no | no | This version predates the affected range (from 3.21.1). |
Sources for CVE-2020-11753 and 3.16.0 Hide sources
| ||||
| CVE-2026-3199 published April 8, 2026 | High8.8 CVSS 3.1 8.8, rated by NVD | no | no | This version predates the affected range (from 3.22.1). |
Sources for CVE-2026-3199 and 3.16.0 Hide sources
| ||||
| CVE-2026-17603 published August 7, 2026 | High8.7 CVSS 4.0 8.7, rated by Sonatype (CNA) | no | no | This version predates the affected range (from 3.20.0). |
Sources for CVE-2026-17603 and 3.16.0 Hide sources
| ||||
| CVE-2026-14644 published August 7, 2026 | High8.6 CVSS 4.0 8.6, rated by Sonatype (CNA) | no | no | This version predates the affected range (from 3.19.0). |
Sources for CVE-2026-14644 and 3.16.0 Hide sources
| ||||
| CVE-2026-14504 published July 14, 2026 | High8.2 CVSS 4.0 8.2, rated by Sonatype (CNA) | no NVD data | no | This version predates the affected range (from 3.88.0). |
Sources for CVE-2026-14504 and 3.16.0 Hide sources
| ||||
| CVE-2018-16620 published November 15, 2018 | High7.5 CVSS 3.0 7.5, rated by NVD | no | no | This version is outside the affected range. |
Sources for CVE-2018-16620 and 3.16.0 Hide sources
| ||||
| CVE-2026-77124 published September 2, 2026 | High7.5 CVSS 4.0 7.5, rated by Sonatype (CNA) | no | no | This version predates the affected range (from 3.21.2). |
Sources for CVE-2026-77124 and 3.16.0 Hide sources
| ||||
| CVE-2018-16621 published November 15, 2018 | High7.2 CVSS 3.1 7.2, rated by NVD | no | no | This version is outside the affected range. |
Sources for CVE-2018-16621 and 3.16.0 Hide sources
| ||||
| CVE-2026-77125 published September 2, 2026 | High7.1 CVSS 4.0 7.1, rated by Sonatype (CNA) | no | no | This version predates the affected range (from 3.19.0). |
Sources for CVE-2026-77125 and 3.16.0 Hide sources
| ||||
| CVE-2026-17599 published August 7, 2026 | Medium6.9 CVSS 4.0 6.9, rated by Sonatype (CNA) | no | no | This version predates the affected range (from 3.17.0). |
Sources for CVE-2026-17599 and 3.16.0 Hide sources
| ||||
| CVE-2018-16619 published November 15, 2018 | Medium6.1 CVSS 3.0 6.1, rated by NVD | no | no | This version is outside the affected range. |
Sources for CVE-2018-16619 and 3.16.0 Hide sources
| ||||
| CVE-2018-5306 published February 9, 2018 | Medium6.1 CVSS 3.0 6.1, rated by NVD | no | no | This version is outside the affected range. |
Sources for CVE-2018-5306 and 3.16.0 Hide sources
| ||||
| CVE-2021-29159 published April 28, 2021 | Medium6.1 CVSS 3.1 6.1, rated by NVD | no | no | This version predates the affected range (from 3.23.0). |
Sources for CVE-2021-29159 and 3.16.0 Hide sources
| ||||
| CVE-2026-17598 published August 7, 2026 | Medium5.3 CVSS 4.0 5.3, rated by Sonatype (CNA) | no | no | This version predates the affected range (from 3.91.0). |
Sources for CVE-2026-17598 and 3.16.0 Hide sources
| ||||
| CVE-2026-77121 published September 2, 2026 | Medium5.3 CVSS 4.0 5.3, rated by Sonatype (CNA) | no | no | This version predates the affected range (from 3.26.0). |
Sources for CVE-2026-77121 and 3.16.0 Hide sources
| ||||
| CVE-2026-77122 published September 2, 2026 | Medium5.3 CVSS 4.0 5.3, rated by Sonatype (CNA) | no | no | This version predates the affected range (from 3.38.0). |
Sources for CVE-2026-77122 and 3.16.0 Hide sources
| ||||
| CVE-2025-13488 published December 4, 2025 | Medium5.1 CVSS 4.0 5.1, rated by Sonatype (CNA) | no NVD data | no | This version predates the affected range (from 3.83.0). |
Sources for CVE-2025-13488 and 3.16.0 Hide sources
| ||||
| CVE-2026-0601 published January 14, 2026 | Medium5.1 CVSS 4.0 5.1, rated by Sonatype (CNA) | no NVD data | no | This version predates the affected range (from 3.82.0). |
Sources for CVE-2026-0601 and 3.16.0 Hide sources
| ||||
| CVE-2018-12100 published June 11, 2018 | Medium4.8 CVSS 3.0 4.8, rated by NVD | no | no | This version is outside the affected range. |
Sources for CVE-2018-12100 and 3.16.0 Hide sources
| ||||
About this page and CloudRepo
CloudRepo is a managed artifact repository, so there is no Artifactory or Nexus server for you to patch. In over 10 years of operation, CloudRepo has experienced no known security breaches. This page is not a scan of your server: the data is NVD's and the vendor's, linked on every row, pulled on September 18, 2026.
Read next
Look up another version