Sonatype Nexus Repository 3.77.2: known vulnerabilities

27 known CVEs affect Sonatype Nexus Repository 3.77.2: 20 by NVD's exact CPE match, and 7 more that Sonatype's advisories list and NVD has not analyzed.

NVD's count evaluates NVD's published version ranges against this version; those ranges do not carry Sonatype's per-branch fixes, so the NVD column can read the same on either side of a fix that Sonatype names. Where NVD has not analyzed a record, the row reads "no NVD data", not "no".

Known CVEs
27
High 12 Medium 15
12 high, 15 medium
Released
February 25, 2025
Per Sonatype's release pages.
End of life
Sonatype status: Sunsetted. General availability ended February 4, 2026. Sunset since August 4, 2026.
Behind latest
570 days behind 3.96.2 (released September 18, 2026).

Sonatype's policy: Sonatype Nexus Repository releases are considered generally available and fully supported for a term of 1 year after the version's release date. Sonatype provides extended maintenance for each Sonatype Nexus Repository version for an additional 6 months before that version is considered sunset.

Sources: NVD (exact CPE match and the published configurations), the CVE Program record (the vendor's CNA entry with its affected and fixed versions), Sonatype's security advisories, release notes and end-of-life page. Pulled September 18, 2026. Every CVE row links to its NVD record and to the vendor's advisory.

CVEs that affect 3.77.2 (27)

Two verdicts per row, side by side: what NVD's exact CPE match says, and what Sonatype's own CVE record says. A CVE counts when either source says affected. Open a row's sources for the raw ranges.

CVEs that affect Sonatype Nexus Repository 3.77.2
CVE-2026-17601 published August 7, 2026

A user holding a permission to update privilege definitions could modify a wildcard privilege already assigned to their own role to grant broader permissions than they were authorized to hold, including full administrative access, without any additional authorization check or role reassignment.

High8.9 CVSS 4.0 8.9, rated by Sonatype (CNA) yes yes No fix on your branch; the nearest fix is 3.95.0. Latest: 3.96.2.
Sources for CVE-2026-17601 and 3.77.2
NVD range
NVD indexes 142 exact versions from the CNA's CPE list (NVD status: Undergoing Analysis): 3.19.0, 3.19.1, 3.20.0, 3.20.1, 3.20.2, 3.20.3, 3.21.0, 3.21.1, 3.21.2, 3.22.0, 3.22.1, 3.23.0, 3.24.0, 3.24.1, 3.25.0, 3.25.1, 3.26.0, 3.26.1, 3.27.0, 3.28.0, 3.28.1, 3.29.0, 3.29.1, 3.29.2, 3.30.0, 3.30.1, 3.31.0, 3.31.1, 3.32.0, 3.32.1, 3.33.0, 3.33.1, 3.34.0, 3.34.1, 3.35.0, 3.36.0, 3.37.0, 3.37.1, 3.37.2, 3.37.3, 3.38.0, 3.38.1, 3.39.0, 3.40.0, 3.40.1, 3.41.0, 3.41.1, 3.42.0, 3.43.0, 3.44.0, 3.45.0, 3.45.1, 3.46.0, 3.47.0, 3.47.1, 3.48.0, 3.49.0, 3.50.0, 3.51.0, 3.52.0, 3.53.0, 3.53.1, 3.54.0, 3.54.1, 3.55.0, 3.56.0, 3.57.0, 3.57.1, 3.58.0, 3.58.1, 3.59.0, 3.60.0, 3.61.0, 3.62.0, 3.63.0, 3.64.0, 3.65.0, 3.66.0, 3.67.0, 3.67.1, 3.68.0, 3.68.1, 3.69.0, 3.70.0, 3.70.1, 3.71.0, 3.72.0, 3.73.0, 3.74.0, 3.75.0, 3.75.1, 3.76.0, 3.76.1, 3.77.0, 3.77.1, 3.77.2, 3.78.0, 3.78.1, 3.78.2, 3.78.3, 3.79.0, 3.79.1, 3.80.0, 3.81.0, 3.81.1, 3.82.0, 3.82.1, 3.83.0, 3.83.1, 3.83.2, 3.84.0, 3.84.1, 3.84.2, 3.85.0, 3.85.1, 3.86.0, 3.86.1, 3.86.2, 3.86.3, 3.87.0, 3.87.1, 3.87.2, 3.88.0, 3.88.1, 3.89.0, 3.89.1, 3.90.0, 3.90.1, 3.90.2, 3.90.3, 3.90.4, 3.91.0, 3.91.1, 3.92.0, 3.92.1, 3.92.2, 3.92.3, 3.93.0, 3.93.1, 3.93.2, 3.94.0, 3.94.1. NVD record
Sonatype range
Sonatype: All Sonatype Nexus Repository 3 CE/Pro versions from 3.19.0 through 3.94.x. Sonatype advisory
CVE-2026-3199 published April 8, 2026

A vulnerability in the task management component of Sonatype Nexus Repository versions 3.22.1 through 3.90.2 allows an authenticated attacker with task creation permissions to execute arbitrary code, bypassing the nexus.scripts.allowCreation security control.

High8.8 CVSS 3.1 8.8, rated by NVD yes yes No fix on your branch; the nearest fix is 3.91.0. Latest: 3.96.2.
Sources for CVE-2026-3199 and 3.77.2
NVD range
NVD configuration (NVD status: Analyzed): from 3.22.1 (including), before 3.91.0. NVD record
Sonatype range
Sonatype: Sonatype Nexus Repository 3.22.1 through 3.90.x (CE/Pro). Sonatype advisory
CVE-2026-11403 published July 14, 2026

A vulnerability in Sonatype Nexus Repository Manager's format-specific API key generation may allow a remote attacker to gain unauthorized access to repository operations as a targeted user. A format-specific API key realm (NuGet API Key, Docker Bearer Token, or npm Bearer Token) must be enabled and the targeted user must have an active API key for this vulnerability to be exploitable.

High8.7 CVSS 4.0 8.7, rated by Sonatype (CNA) yes yes No fix on your branch; the nearest fix is 3.93.0. Latest: 3.96.2.
Sources for CVE-2026-11403 and 3.77.2
NVD range
NVD indexes 176 exact versions from the CNA's CPE list (NVD status: Undergoing Analysis): 3.0.0, 3.0.1, 3.0.2, 3.1.0, 3.2.0, 3.2.1, 3.3.0, 3.3.1, 3.3.2, 3.4.0, 3.5.0, 3.5.1, 3.5.2, 3.6.0, 3.6.1, 3.6.2, 3.7.0, 3.7.1, 3.8.0, 3.9.0, 3.10.0, 3.11.0, 3.12.0, 3.12.1, 3.13.0, 3.14.0, 3.15.0, 3.15.1, 3.15.2, 3.16.0, 3.16.1, 3.16.2, 3.17.0, 3.18.0, 3.18.1, 3.19.0, 3.19.1, 3.20.0, 3.20.1, 3.20.2, 3.20.3, 3.21.0, 3.21.1, 3.21.2, 3.22.0, 3.22.1, 3.23.0, 3.24.0, 3.24.1, 3.25.0, 3.25.1, 3.26.0, 3.26.1, 3.27.0, 3.28.0, 3.28.1, 3.29.0, 3.29.1, 3.29.2, 3.30.0, 3.30.1, 3.31.0, 3.31.1, 3.32.0, 3.32.1, 3.33.0, 3.33.1, 3.34.0, 3.34.1, 3.35.0, 3.36.0, 3.37.0, 3.37.1, 3.37.2, 3.37.3, 3.38.0, 3.38.1, 3.39.0, 3.40.0, 3.40.1, 3.41.0, 3.41.1, 3.42.0, 3.43.0, 3.44.0, 3.45.0, 3.45.1, 3.46.0, 3.47.0, 3.47.1, 3.48.0, 3.49.0, 3.50.0, 3.51.0, 3.52.0, 3.53.0, 3.53.1, 3.54.0, 3.54.1, 3.55.0, 3.56.0, 3.57.0, 3.57.1, 3.58.0, 3.58.1, 3.59.0, 3.60.0, 3.61.0, 3.62.0, 3.63.0, 3.64.0, 3.65.0, 3.66.0, 3.67.0, 3.67.1, 3.68.0, 3.68.1, 3.69.0, 3.70.0, 3.70.1, 3.70.2, 3.70.3, 3.70.4, 3.70.5, 3.71.0, 3.72.0, 3.73.0, 3.74.0, 3.75.0, 3.75.1, 3.76.0, 3.76.1, 3.77.0, 3.77.1, 3.77.2, 3.78.0, 3.78.1, 3.78.2, 3.78.3, 3.79.0, 3.79.1, 3.80.0, 3.81.0, 3.81.1, 3.82.0, 3.82.1, 3.83.0, 3.83.1, 3.83.2, 3.84.0, 3.84.1, 3.84.2, 3.85.0, 3.85.1, 3.86.0, 3.86.1, 3.86.2, 3.86.3, 3.87.0, 3.87.1, 3.87.2, 3.88.0, 3.88.1, 3.89.0, 3.89.1, 3.90.0, 3.90.1, 3.90.2, 3.90.3, 3.90.4, 3.91.0, 3.91.1, 3.92.0, 3.92.1, 3.92.2, 3.92.3. NVD record
Sonatype range
Sonatype: All Sonatype Nexus Repository 3.x CE/Pro versions before 3.93.0. Sonatype advisory
CVE-2026-17600 published August 7, 2026

Sonatype Nexus Repository 3 did not immediately terminate a user's active login session or revoke their cached permissions when that user's account was deleted, deactivated, or had its password changed. A user whose account was already logged in at the time of one of these actions could continue using their existing session to interact with the repository as though the account were still active, until that session independently expired. Depending on the permissions previously held, this could allow continued unauthorized access to read, modify, or delete repository content after access was intended to be revoked.

High8.7 CVSS 4.0 8.7, rated by Sonatype (CNA) yes yes No fix on your branch; the nearest fix is 3.95.0. Latest: 3.96.2.
Sources for CVE-2026-17600 and 3.77.2
NVD range
NVD indexes 180 exact versions from the CNA's CPE list (NVD status: Undergoing Analysis): 3.0.0, 3.0.1, 3.0.2, 3.1.0, 3.2.0, 3.2.1, 3.3.0, 3.3.1, 3.3.2, 3.4.0, 3.5.0, 3.5.1, 3.5.2, 3.6.0, 3.6.1, 3.6.2, 3.7.0, 3.7.1, 3.8.0, 3.9.0, 3.10.0, 3.11.0, 3.12.0, 3.12.1, 3.13.0, 3.14.0, 3.15.0, 3.15.1, 3.15.2, 3.15.3, 3.16.0, 3.16.1, 3.16.2, 3.17.0, 3.17.1, 3.17.2, 3.18.0, 3.18.1, 3.19.0, 3.19.1, 3.20.0, 3.20.1, 3.20.2, 3.20.3, 3.21.0, 3.21.1, 3.21.2, 3.22.0, 3.22.1, 3.23.0, 3.24.0, 3.24.1, 3.25.0, 3.25.1, 3.26.0, 3.26.1, 3.27.0, 3.28.0, 3.28.1, 3.29.0, 3.29.1, 3.29.2, 3.30.0, 3.30.1, 3.31.0, 3.31.1, 3.32.0, 3.32.1, 3.33.0, 3.33.1, 3.34.0, 3.34.1, 3.35.0, 3.36.0, 3.37.0, 3.37.1, 3.37.2, 3.37.3, 3.38.0, 3.38.1, 3.39.0, 3.40.0, 3.40.1, 3.41.0, 3.41.1, 3.42.0, 3.43.0, 3.44.0, 3.45.0, 3.45.1, 3.46.0, 3.47.0, 3.47.1, 3.48.0, 3.49.0, 3.50.0, 3.51.0, 3.52.0, 3.53.0, 3.53.1, 3.54.0, 3.54.1, 3.55.0, 3.56.0, 3.57.0, 3.57.1, 3.58.0, 3.58.1, 3.59.0, 3.60.0, 3.61.0, 3.62.0, 3.63.0, 3.64.0, 3.65.0, 3.66.0, 3.67.0, 3.67.1, 3.68.0, 3.68.1, 3.69.0, 3.70.0, 3.70.1, 3.71.0, 3.72.0, 3.73.0, 3.74.0, 3.75.0, 3.75.1, 3.76.0, 3.76.1, 3.77.0, 3.77.1, 3.77.2, 3.78.0, 3.78.1, 3.78.2, 3.78.3, 3.79.0, 3.79.1, 3.80.0, 3.81.0, 3.81.1, 3.82.0, 3.82.1, 3.83.0, 3.83.1, 3.83.2, 3.84.0, 3.84.1, 3.84.2, 3.85.0, 3.85.1, 3.86.0, 3.86.1, 3.86.2, 3.86.3, 3.87.0, 3.87.1, 3.87.2, 3.88.0, 3.88.1, 3.89.0, 3.89.1, 3.90.0, 3.90.1, 3.90.2, 3.90.3, 3.90.4, 3.91.0, 3.91.1, 3.92.0, 3.92.1, 3.92.2, 3.92.3, 3.93.0, 3.93.1, 3.93.2, 3.94.0, 3.94.1. NVD record
Sonatype range
Sonatype: All Sonatype Nexus Repository CE/Pro versions prior to 3.95.0. Sonatype advisory
CVE-2026-17603 published August 7, 2026

Nexus Repository 3 did not sufficiently restrict which HikariCP connection-pool properties could be set through the DataStore configuration API. A user holding the nx-datastores-update permission could set the connectionInitSql property to execute arbitrary SQL against the configured database on every new connection. On the default H2 database backend, this could be leveraged to achieve remote code execution as the Nexus process user.

High8.7 CVSS 4.0 8.7, rated by Sonatype (CNA) yes yes No fix on your branch; the nearest fix is 3.95.0. Latest: 3.96.2.
Sources for CVE-2026-17603 and 3.77.2
NVD range
NVD indexes 140 exact versions from the CNA's CPE list (NVD status: Undergoing Analysis): 3.20.0, 3.20.1, 3.20.2, 3.20.3, 3.21.0, 3.21.1, 3.21.2, 3.22.0, 3.22.1, 3.23.0, 3.24.0, 3.24.1, 3.25.0, 3.25.1, 3.26.0, 3.26.1, 3.27.0, 3.28.0, 3.28.1, 3.29.0, 3.29.1, 3.29.2, 3.30.0, 3.30.1, 3.31.0, 3.31.1, 3.32.0, 3.32.1, 3.33.0, 3.33.1, 3.34.0, 3.34.1, 3.35.0, 3.36.0, 3.37.0, 3.37.1, 3.37.2, 3.37.3, 3.38.0, 3.38.1, 3.39.0, 3.40.0, 3.40.1, 3.41.0, 3.41.1, 3.42.0, 3.43.0, 3.44.0, 3.45.0, 3.45.1, 3.46.0, 3.47.0, 3.47.1, 3.48.0, 3.49.0, 3.50.0, 3.51.0, 3.52.0, 3.53.0, 3.53.1, 3.54.0, 3.54.1, 3.55.0, 3.56.0, 3.57.0, 3.57.1, 3.58.0, 3.58.1, 3.59.0, 3.60.0, 3.61.0, 3.62.0, 3.63.0, 3.64.0, 3.65.0, 3.66.0, 3.67.0, 3.67.1, 3.68.0, 3.68.1, 3.69.0, 3.70.0, 3.70.1, 3.71.0, 3.72.0, 3.73.0, 3.74.0, 3.75.0, 3.75.1, 3.76.0, 3.76.1, 3.77.0, 3.77.1, 3.77.2, 3.78.0, 3.78.1, 3.78.2, 3.78.3, 3.79.0, 3.79.1, 3.80.0, 3.81.0, 3.81.1, 3.82.0, 3.82.1, 3.83.0, 3.83.1, 3.83.2, 3.84.0, 3.84.1, 3.84.2, 3.85.0, 3.85.1, 3.86.0, 3.86.1, 3.86.2, 3.86.3, 3.87.0, 3.87.1, 3.87.2, 3.88.0, 3.88.1, 3.89.0, 3.89.1, 3.90.0, 3.90.1, 3.90.2, 3.90.3, 3.90.4, 3.91.0, 3.91.1, 3.92.0, 3.92.1, 3.92.2, 3.92.3, 3.93.0, 3.93.1, 3.93.2, 3.94.0, 3.94.1. NVD record
Sonatype range
Sonatype: All Nexus Repository 3 CE/Pro versions from 3.20.0 up to and including 3.94.x. Sonatype advisory
CVE-2026-10748 published June 16, 2026

An authenticated user with the nx-licensing-create privilege can upload a specially crafted license file to execute arbitrary operating system commands as the Nexus process user in Sonatype Nexus Repository 3 versions before 3.92.0.

High8.6 CVSS 4.0 8.6, rated by Sonatype (CNA) no yes No fix on your branch; the nearest fix is 3.92.0. Latest: 3.96.2.
Sources for CVE-2026-10748 and 3.77.2
NVD range
NVD indexes 158 exact versions from the CNA's CPE list (NVD status: Undergoing Analysis): 3.0.0, 3.0.1, 3.0.2, 3.1.0, 3.2.0, 3.2.1, 3.3.0, 3.3.1, 3.3.2, 3.4.0, 3.5.0, 3.5.1, 3.5.2, 3.6.0, 3.6.1, 3.6.2, 3.7.0, 3.7.1, 3.8.0, 3.9.0, 3.10.0, 3.11.0, 3.12.0, 3.12.1, 3.13.0, 3.14.0, 3.15.0, 3.15.1, 3.15.2, 3.16.0, 3.16.1, 3.16.2, 3.17.0, 3.18.0, 3.18.1, 3.19.0, 3.19.1, 3.20.0, 3.20.1, 3.21.0, 3.21.1, 3.21.2, 3.22.0, 3.22.1, 3.23.0, 3.24.0, 3.25.0, 3.25.1, 3.26.0, 3.26.1, 3.27.0, 3.28.0, 3.28.1, 3.29.0, 3.29.2, 3.30.0, 3.30.1, 3.31.0, 3.31.1, 3.32.0, 3.32.1, 3.33.0, 3.33.1, 3.34.0, 3.34.1, 3.35.0, 3.36.0, 3.37.0, 3.37.1, 3.37.2, 3.37.3, 3.38.0, 3.38.1, 3.39.0, 3.40.0, 3.40.1, 3.41.0, 3.41.1, 3.42.0, 3.43.0, 3.44.0, 3.45.0, 3.45.1, 3.46.0, 3.47.0, 3.47.1, 3.48.0, 3.49.0, 3.50.0, 3.51.0, 3.52.0, 3.53.0, 3.53.1, 3.54.0, 3.54.1, 3.55.0, 3.56.0, 3.57.0, 3.57.1, 3.58.0, 3.58.1, 3.59.0, 3.60.0, 3.61.0, 3.62.0, 3.63.0, 3.64.0, 3.65.0, 3.66.0, 3.67.0, 3.67.1, 3.68.0, 3.68.1, 3.69.0, 3.70.0, 3.70.1, 3.70.2, 3.70.3, 3.70.4, 3.70.5, 3.71.0, 3.72.0, 3.73.0, 3.74.0, 3.75.0, 3.75.1, 3.76.0, 3.76.1, 3.77.0, 3.78.0, 3.78.1, 3.79.0, 3.80.0, 3.81.0, 3.82.0, 3.83.0, 3.83.1, 3.83.2, 3.84.0, 3.84.1, 3.84.2, 3.85.0, 3.85.1, 3.86.0, 3.86.2, 3.86.3, 3.87.0, 3.87.1, 3.87.2, 3.88.0, 3.89.0, 3.89.1, 3.90.0, 3.90.1, 3.90.2, 3.90.3, 3.91.0, 3.91.1. NVD record
Sonatype range
Sonatype: All Sonatype Nexus Repository 3.x CE/Pro versions before 3.92.0. Sonatype advisory
CVE-2026-14644 published August 7, 2026

Nexus Repository 3 contained a privilege escalation vulnerability in the REST privileges API. An authenticated user with permission to manage privileges could, under certain role configurations, escalate their own access to full administrator by exploiting a type-confusion flaw in the privilege update endpoint.

High8.6 CVSS 4.0 8.6, rated by Sonatype (CNA) yes yes No fix on your branch; the nearest fix is 3.95.0. Latest: 3.96.2.
Sources for CVE-2026-14644 and 3.77.2
NVD range
NVD indexes 146 exact versions from the CNA's CPE list (NVD status: Undergoing Analysis): 3.19.0, 3.19.1, 3.20.0, 3.20.1, 3.20.2, 3.20.3, 3.21.0, 3.21.1, 3.21.2, 3.22.0, 3.22.1, 3.23.0, 3.24.0, 3.24.1, 3.25.0, 3.25.1, 3.26.0, 3.26.1, 3.27.0, 3.28.0, 3.28.1, 3.29.0, 3.29.1, 3.29.2, 3.30.0, 3.30.1, 3.31.0, 3.31.1, 3.32.0, 3.32.1, 3.33.0, 3.33.1, 3.34.0, 3.34.1, 3.35.0, 3.36.0, 3.37.0, 3.37.1, 3.37.2, 3.37.3, 3.38.0, 3.38.1, 3.39.0, 3.40.0, 3.40.1, 3.41.0, 3.41.1, 3.42.0, 3.43.0, 3.44.0, 3.45.0, 3.45.1, 3.46.0, 3.47.0, 3.47.1, 3.48.0, 3.49.0, 3.50.0, 3.51.0, 3.52.0, 3.53.0, 3.53.1, 3.54.0, 3.54.1, 3.55.0, 3.56.0, 3.57.0, 3.57.1, 3.58.0, 3.58.1, 3.59.0, 3.60.0, 3.61.0, 3.62.0, 3.63.0, 3.64.0, 3.65.0, 3.66.0, 3.67.0, 3.67.1, 3.68.0, 3.68.1, 3.69.0, 3.70.0, 3.70.1, 3.70.2, 3.70.3, 3.70.4, 3.70.5, 3.71.0, 3.72.0, 3.73.0, 3.74.0, 3.75.0, 3.75.1, 3.76.0, 3.76.1, 3.77.0, 3.77.1, 3.77.2, 3.78.0, 3.78.1, 3.78.2, 3.78.3, 3.79.0, 3.79.1, 3.80.0, 3.81.0, 3.81.1, 3.82.0, 3.82.1, 3.83.0, 3.83.1, 3.83.2, 3.84.0, 3.84.1, 3.84.2, 3.85.0, 3.85.1, 3.86.0, 3.86.1, 3.86.2, 3.86.3, 3.87.0, 3.87.1, 3.87.2, 3.88.0, 3.88.1, 3.89.0, 3.89.1, 3.90.0, 3.90.1, 3.90.2, 3.90.3, 3.90.4, 3.91.0, 3.91.1, 3.92.0, 3.92.1, 3.92.2, 3.92.3, 3.93.0, 3.93.1, 3.93.2, 3.94.0, 3.94.1. NVD record
Sonatype range
Sonatype: All previous Sonatype Nexus Repository 3 CE/Pro versions 3.19.0 through 3.94.x. Sonatype advisory
CVE-2026-17594 published August 7, 2026

Nexus Repository 3 CE/Pro versions 3.0.0 through 3.94.x contain an incorrect authorization vulnerability (CWE-863) in the repository-creation user interface. An individual user account holding a delegated repository-admin privilege scoped to a specific repository format could create a repository of a different, unauthorized format, because authorization was checked against one request field while a separate, attacker-controlled field determined the repository format actually created. This does not affect the anonymous user, which cannot hold this privilege by default. Fixed in version 3.95.0.

High8.2 CVSS 4.0 8.2, rated by Sonatype (CNA) yes yes No fix on your branch; the nearest fix is 3.95.0. Latest: 3.96.2.
Sources for CVE-2026-17594 and 3.77.2
NVD range
NVD indexes 180 exact versions from the CNA's CPE list (NVD status: Undergoing Analysis): 3.0.0, 3.0.1, 3.0.2, 3.1.0, 3.2.0, 3.2.1, 3.3.0, 3.3.1, 3.3.2, 3.4.0, 3.5.0, 3.5.1, 3.5.2, 3.6.0, 3.6.1, 3.6.2, 3.7.0, 3.7.1, 3.8.0, 3.9.0, 3.10.0, 3.11.0, 3.12.0, 3.12.1, 3.13.0, 3.14.0, 3.15.0, 3.15.1, 3.15.2, 3.15.3, 3.16.0, 3.16.1, 3.16.2, 3.17.0, 3.17.1, 3.17.2, 3.18.0, 3.18.1, 3.19.0, 3.19.1, 3.20.0, 3.20.1, 3.20.2, 3.20.3, 3.21.0, 3.21.1, 3.21.2, 3.22.0, 3.22.1, 3.23.0, 3.24.0, 3.24.1, 3.25.0, 3.25.1, 3.26.0, 3.26.1, 3.27.0, 3.28.0, 3.28.1, 3.29.0, 3.29.1, 3.29.2, 3.30.0, 3.30.1, 3.31.0, 3.31.1, 3.32.0, 3.32.1, 3.33.0, 3.33.1, 3.34.0, 3.34.1, 3.35.0, 3.36.0, 3.37.0, 3.37.1, 3.37.2, 3.37.3, 3.38.0, 3.38.1, 3.39.0, 3.40.0, 3.40.1, 3.41.0, 3.41.1, 3.42.0, 3.43.0, 3.44.0, 3.45.0, 3.45.1, 3.46.0, 3.47.0, 3.47.1, 3.48.0, 3.49.0, 3.50.0, 3.51.0, 3.52.0, 3.53.0, 3.53.1, 3.54.0, 3.54.1, 3.55.0, 3.56.0, 3.57.0, 3.57.1, 3.58.0, 3.58.1, 3.59.0, 3.60.0, 3.61.0, 3.62.0, 3.63.0, 3.64.0, 3.65.0, 3.66.0, 3.67.0, 3.67.1, 3.68.0, 3.68.1, 3.69.0, 3.70.0, 3.70.1, 3.71.0, 3.72.0, 3.73.0, 3.74.0, 3.75.0, 3.75.1, 3.76.0, 3.76.1, 3.77.0, 3.77.1, 3.77.2, 3.78.0, 3.78.1, 3.78.2, 3.78.3, 3.79.0, 3.79.1, 3.80.0, 3.81.0, 3.81.1, 3.82.0, 3.82.1, 3.83.0, 3.83.1, 3.83.2, 3.84.0, 3.84.1, 3.84.2, 3.85.0, 3.85.1, 3.86.0, 3.86.1, 3.86.2, 3.86.3, 3.87.0, 3.87.1, 3.87.2, 3.88.0, 3.88.1, 3.89.0, 3.89.1, 3.90.0, 3.90.1, 3.90.2, 3.90.3, 3.90.4, 3.91.0, 3.91.1, 3.92.0, 3.92.1, 3.92.2, 3.92.3, 3.93.0, 3.93.1, 3.93.2, 3.94.0, 3.94.1. NVD record
Sonatype range
Sonatype: All previous Sonatype Nexus Repository 3 CE/Pro versions 3.0.0 through 3.94.x. Sonatype advisory
CVE-2026-3329 published June 11, 2026

A remote unauthenticated attacker may be able to conduct credential-guessing attacks against user accounts in Sonatype Nexus Repository via authentication endpoints.

High7.5 CVSS 3.1 7.5, rated by NVD yes yes No fix on your branch; the nearest fix is 3.93.0. Latest: 3.96.2.
Sources for CVE-2026-3329 and 3.77.2
NVD range
NVD configuration (NVD status: Analyzed): from 3.0.0 (including), before 3.93.0. NVD record
Sonatype range
Sonatype: All Sonatype Nexus Repository versions from 3.0.0 up to and including 3.92.x. Sonatype advisory
CVE-2026-77124 published September 2, 2026

In affected versions of Nexus Repository 3, the script execution endpoint (POST /service/rest/v1/script/{name}/run) did not verify whether script execution had been administratively disabled. An account holding script-execution permission could continue to run previously-created scripts even after an administrator set nexus.scripts.allowCreation=false, undermining the expectation that this setting fully blocks script execution.

High7.5 CVSS 4.0 7.5, rated by Sonatype (CNA) yes yes No fix on your branch; the nearest fix is 3.96.0. Latest: 3.96.2.
Sources for CVE-2026-77124 and 3.77.2
NVD range
NVD indexes 139 exact versions from the CNA's CPE list (NVD status: Undergoing Analysis): 3.21.2, 3.22.0, 3.22.1, 3.23.0, 3.24.0, 3.24.1, 3.25.0, 3.25.1, 3.26.0, 3.26.1, 3.27.0, 3.28.0, 3.28.1, 3.29.0, 3.29.1, 3.29.2, 3.30.0, 3.30.1, 3.31.0, 3.31.1, 3.32.0, 3.32.1, 3.33.0, 3.33.1, 3.34.0, 3.34.1, 3.35.0, 3.36.0, 3.37.0, 3.37.1, 3.37.2, 3.37.3, 3.38.0, 3.38.1, 3.39.0, 3.40.0, 3.40.1, 3.41.0, 3.41.1, 3.42.0, 3.43.0, 3.44.0, 3.45.0, 3.45.1, 3.46.0, 3.47.0, 3.47.1, 3.48.0, 3.49.0, 3.50.0, 3.51.0, 3.52.0, 3.53.0, 3.53.1, 3.54.0, 3.54.1, 3.55.0, 3.56.0, 3.57.0, 3.57.1, 3.58.0, 3.58.1, 3.59.0, 3.60.0, 3.61.0, 3.62.0, 3.63.0, 3.64.0, 3.65.0, 3.66.0, 3.67.0, 3.67.1, 3.68.0, 3.68.1, 3.69.0, 3.70.0, 3.70.1, 3.71.0, 3.72.0, 3.73.0, 3.74.0, 3.75.0, 3.75.1, 3.76.0, 3.76.1, 3.77.0, 3.77.1, 3.77.2, 3.78.0, 3.78.1, 3.78.2, 3.78.3, 3.79.0, 3.79.1, 3.80.0, 3.81.0, 3.81.1, 3.82.0, 3.82.1, 3.83.0, 3.83.1, 3.83.2, 3.84.0, 3.84.1, 3.84.2, 3.85.0, 3.85.1, 3.86.0, 3.86.1, 3.86.2, 3.86.3, 3.87.0, 3.87.1, 3.87.2, 3.88.0, 3.88.1, 3.89.0, 3.89.1, 3.90.0, 3.90.1, 3.90.2, 3.90.3, 3.90.4, 3.90.5, 3.91.0, 3.91.1, 3.92.0, 3.92.1, 3.92.2, 3.92.3, 3.93.0, 3.93.1, 3.93.2, 3.94.0, 3.94.1, 3.95.0, 3.95.1, 3.95.2, 3.95.3. NVD record
Sonatype range
Sonatype: All previous Sonatype Nexus Repository 3 CE/Pro versions from 3.21.2 up to and including 3.95.x. Sonatype advisory
CVE-2026-17593 published August 7, 2026

An account holding the nexus:settings:update permission in Nexus Repository 3 (or the equivalent nexus:settings permission in the legacy Nexus Repository 2) could submit arbitrary values as realm identifiers through an internal configuration API that did not validate them against the set of registered realms. Because unrecognized entries were persisted and re-evaluated on every realm load via a legacy code path, this could result in unintended code executing inside the Nexus Repository process, and in some cases a persistent authentication lockout that was not visible through the administrative UI.

High7.2 CVSS 4.0 7.2, rated by Sonatype (CNA) yes yes No fix on your branch; the nearest fix is 3.95.0. Latest: 3.96.2.
Sources for CVE-2026-17593 and 3.77.2
NVD range
NVD indexes 219 exact versions from the CNA's CPE list (NVD status: Undergoing Analysis): 2.8.0, 2.8.1, 2.9.0, 2.9.1, 2.9.2, 2.10.0, 2.11.0, 2.11.1, 2.11.2, 2.11.3, 2.11.4, 2.12.0, 2.12.1, 2.13.0, 2.14.0, 2.14.1, 2.14.2, 2.14.3, 2.14.4, 2.14.5, 2.14.6, 2.14.7, 2.14.8, 2.14.9, 2.14.10, 2.14.11, 2.14.12, 2.14.13, 2.14.14, 2.14.15, 2.14.16, 2.14.17, 2.14.18, 2.14.19, 2.14.20, 2.14.21, 2.15.0, 2.15.1, 2.15.2, 3.0.0, 3.0.1, 3.0.2, 3.1.0, 3.2.0, 3.2.1, 3.3.0, 3.3.1, 3.3.2, 3.4.0, 3.5.0, 3.5.1, 3.5.2, 3.6.0, 3.6.1, 3.6.2, 3.7.0, 3.7.1, 3.8.0, 3.9.0, 3.10.0, 3.11.0, 3.12.0, 3.12.1, 3.13.0, 3.14.0, 3.15.0, 3.15.1, 3.15.2, 3.15.3, 3.16.0, 3.16.1, 3.16.2, 3.17.0, 3.17.1, 3.17.2, 3.18.0, 3.18.1, 3.19.0, 3.19.1, 3.20.0, 3.20.1, 3.20.2, 3.20.3, 3.21.0, 3.21.1, 3.21.2, 3.22.0, 3.22.1, 3.23.0, 3.24.0, 3.24.1, 3.25.0, 3.25.1, 3.26.0, 3.26.1, 3.27.0, 3.28.0, 3.28.1, 3.29.0, 3.29.1, 3.29.2, 3.30.0, 3.30.1, 3.31.0, 3.31.1, 3.32.0, 3.32.1, 3.33.0, 3.33.1, 3.34.0, 3.34.1, 3.35.0, 3.36.0, 3.37.0, 3.37.1, 3.37.2, 3.37.3, 3.38.0, 3.38.1, 3.39.0, 3.40.0, 3.40.1, 3.41.0, 3.41.1, 3.42.0, 3.43.0, 3.44.0, 3.45.0, 3.45.1, 3.46.0, 3.47.0, 3.47.1, 3.48.0, 3.49.0, 3.50.0, 3.51.0, 3.52.0, 3.53.0, 3.53.1, 3.54.0, 3.54.1, 3.55.0, 3.56.0, 3.57.0, 3.57.1, 3.58.0, 3.58.1, 3.59.0, 3.60.0, 3.61.0, 3.62.0, 3.63.0, 3.64.0, 3.65.0, 3.66.0, 3.67.0, 3.67.1, 3.68.0, 3.68.1, 3.69.0, 3.70.0, 3.70.1, 3.71.0, 3.72.0, 3.73.0, 3.74.0, 3.75.0, 3.75.1, 3.76.0, 3.76.1, 3.77.0, 3.77.1, 3.77.2, 3.78.0, 3.78.1, 3.78.2, 3.78.3, 3.79.0, 3.79.1, 3.80.0, 3.81.0, 3.81.1, 3.82.0, 3.82.1, 3.83.0, 3.83.1, 3.83.2, 3.84.0, 3.84.1, 3.84.2, 3.85.0, 3.85.1, 3.86.0, 3.86.1, 3.86.2, 3.86.3, 3.87.0, 3.87.1, 3.87.2, 3.88.0, 3.88.1, 3.89.0, 3.89.1, 3.90.0, 3.90.1, 3.90.2, 3.90.3, 3.90.4, 3.91.0, 3.91.1, 3.92.0, 3.92.1, 3.92.2, 3.92.3, 3.93.0, 3.93.1, 3.93.2, 3.94.0, 3.94.1. NVD record
Sonatype range
Sonatype: All previous Sonatype Nexus Repository CE/Pro versions from 2.8.0 up to and including 3.94.x. Sonatype advisory
CVE-2026-77125 published September 2, 2026

A vulnerability was identified in Sonatype Nexus Repository 3 in which two blobstore group management REST API endpoints did not correctly enforce the intended authorization check. A user granted only the nexus:blobstores:create permission could invoke these endpoints to convert an existing blobstore into a group blobstore, an action that should require the nexus:blobstores:update permission instead. This could result in unauthorized modification of blobstore configuration without administrator approval. The nexus:blobstores:create permission is a named permission that must be explicitly granted by an administrator; it is not held by default.

High7.1 CVSS 4.0 7.1, rated by Sonatype (CNA) yes yes No fix on your branch; the nearest fix is 3.96.0. Latest: 3.96.2.
Sources for CVE-2026-77125 and 3.77.2
NVD range
NVD indexes 147 exact versions from the CNA's CPE list (NVD status: Undergoing Analysis): 3.19.0, 3.19.1, 3.20.0, 3.20.1, 3.20.2, 3.20.3, 3.21.0, 3.21.1, 3.21.2, 3.22.0, 3.22.1, 3.23.0, 3.24.0, 3.24.1, 3.25.0, 3.25.1, 3.26.0, 3.26.1, 3.27.0, 3.28.0, 3.28.1, 3.29.0, 3.29.1, 3.29.2, 3.30.0, 3.30.1, 3.31.0, 3.31.1, 3.32.0, 3.32.1, 3.33.0, 3.33.1, 3.34.0, 3.34.1, 3.35.0, 3.36.0, 3.37.0, 3.37.1, 3.37.2, 3.37.3, 3.38.0, 3.38.1, 3.39.0, 3.40.0, 3.40.1, 3.41.0, 3.41.1, 3.42.0, 3.43.0, 3.44.0, 3.45.0, 3.45.1, 3.46.0, 3.47.0, 3.47.1, 3.48.0, 3.49.0, 3.50.0, 3.51.0, 3.52.0, 3.53.0, 3.53.1, 3.54.0, 3.54.1, 3.55.0, 3.56.0, 3.57.0, 3.57.1, 3.58.0, 3.58.1, 3.59.0, 3.60.0, 3.61.0, 3.62.0, 3.63.0, 3.64.0, 3.65.0, 3.66.0, 3.67.0, 3.67.1, 3.68.0, 3.68.1, 3.69.0, 3.70.0, 3.70.1, 3.71.0, 3.72.0, 3.73.0, 3.74.0, 3.75.0, 3.75.1, 3.76.0, 3.76.1, 3.77.0, 3.77.1, 3.77.2, 3.78.0, 3.78.1, 3.78.2, 3.78.3, 3.79.0, 3.79.1, 3.80.0, 3.81.0, 3.81.1, 3.82.0, 3.82.1, 3.83.0, 3.83.1, 3.83.2, 3.84.0, 3.84.1, 3.84.2, 3.85.0, 3.85.1, 3.86.0, 3.86.1, 3.86.2, 3.86.3, 3.87.0, 3.87.1, 3.87.2, 3.88.0, 3.88.1, 3.89.0, 3.89.1, 3.90.0, 3.90.1, 3.90.2, 3.90.3, 3.90.4, 3.90.5, 3.91.0, 3.91.1, 3.92.0, 3.92.1, 3.92.2, 3.92.3, 3.93.0, 3.93.1, 3.93.2, 3.94.0, 3.94.1, 3.95.0, 3.95.1, 3.95.2, 3.95.3. NVD record
Sonatype range
Sonatype: All Sonatype Nexus Repository 3 CE/Pro versions from 3.19.0 up to and including 3.95.x. Sonatype advisory
CVE-2026-17599 published August 7, 2026

Nexus Repository 3 contained an endpoint used to change the administrator account password during initial onboarding. This endpoint did not verify that onboarding was still in progress before allowing the password change, relying instead on the presence of a local onboarding artifact. As a result, an account holding the nexus:* permission could invoke the endpoint outside the intended onboarding flow to replace the administrator password, and existing sessions were not invalidated after the change.

Medium6.9 CVSS 4.0 6.9, rated by Sonatype (CNA) yes yes No fix on your branch; the nearest fix is 3.95.0. Latest: 3.96.2.
Sources for CVE-2026-17599 and 3.77.2
NVD range
NVD indexes 147 exact versions from the CNA's CPE list (NVD status: Undergoing Analysis): 3.17.0, 3.17.1, 3.17.2, 3.18.0, 3.18.1, 3.19.0, 3.19.1, 3.20.0, 3.20.1, 3.20.2, 3.20.3, 3.21.0, 3.21.1, 3.21.2, 3.22.0, 3.22.1, 3.23.0, 3.24.0, 3.24.1, 3.25.0, 3.25.1, 3.26.0, 3.26.1, 3.27.0, 3.28.0, 3.28.1, 3.29.0, 3.29.1, 3.29.2, 3.30.0, 3.30.1, 3.31.0, 3.31.1, 3.32.0, 3.32.1, 3.33.0, 3.33.1, 3.34.0, 3.34.1, 3.35.0, 3.36.0, 3.37.0, 3.37.1, 3.37.2, 3.37.3, 3.38.0, 3.38.1, 3.39.0, 3.40.0, 3.40.1, 3.41.0, 3.41.1, 3.42.0, 3.43.0, 3.44.0, 3.45.0, 3.45.1, 3.46.0, 3.47.0, 3.47.1, 3.48.0, 3.49.0, 3.50.0, 3.51.0, 3.52.0, 3.53.0, 3.53.1, 3.54.0, 3.54.1, 3.55.0, 3.56.0, 3.57.0, 3.57.1, 3.58.0, 3.58.1, 3.59.0, 3.60.0, 3.61.0, 3.62.0, 3.63.0, 3.64.0, 3.65.0, 3.66.0, 3.67.0, 3.67.1, 3.68.0, 3.68.1, 3.69.0, 3.70.0, 3.70.1, 3.71.0, 3.72.0, 3.73.0, 3.74.0, 3.75.0, 3.75.1, 3.76.0, 3.76.1, 3.77.0, 3.77.1, 3.77.2, 3.78.0, 3.78.1, 3.78.2, 3.78.3, 3.79.0, 3.79.1, 3.80.0, 3.81.0, 3.81.1, 3.82.0, 3.82.1, 3.83.0, 3.83.1, 3.83.2, 3.84.0, 3.84.1, 3.84.2, 3.85.0, 3.85.1, 3.86.0, 3.86.1, 3.86.2, 3.86.3, 3.87.0, 3.87.1, 3.87.2, 3.88.0, 3.88.1, 3.89.0, 3.89.1, 3.90.0, 3.90.1, 3.90.2, 3.90.3, 3.90.4, 3.91.0, 3.91.1, 3.92.0, 3.92.1, 3.92.2, 3.92.3, 3.93.0, 3.93.1, 3.93.2, 3.94.0, 3.94.1. NVD record
Sonatype range
Sonatype: All previous Nexus Repository 3 CE/Pro versions from 3.17.0 up to and including 3.94.x. Sonatype advisory
CVE-2026-17596 published August 7, 2026

Nexus Repository 3 was found to be vulnerable to stored cross-site scripting (XSS). A user with the nexus:blobstores:create or nexus:blobstores:update permission could set a blob store name containing malicious script content, which would later execute in the browser of another user viewing system health-check status. This issue has been fixed in version 3.95.0.

Medium6.3 CVSS 4.0 6.3, rated by Sonatype (CNA) yes yes No fix on your branch; the nearest fix is 3.95.0. Latest: 3.96.2.
Sources for CVE-2026-17596 and 3.77.2
NVD range
NVD indexes 150 exact versions from the CNA's CPE list (NVD status: Undergoing Analysis): 3.16.0, 3.16.1, 3.16.2, 3.17.0, 3.17.1, 3.17.2, 3.18.0, 3.18.1, 3.19.0, 3.19.1, 3.20.0, 3.20.1, 3.20.2, 3.20.3, 3.21.0, 3.21.1, 3.21.2, 3.22.0, 3.22.1, 3.23.0, 3.24.0, 3.24.1, 3.25.0, 3.25.1, 3.26.0, 3.26.1, 3.27.0, 3.28.0, 3.28.1, 3.29.0, 3.29.1, 3.29.2, 3.30.0, 3.30.1, 3.31.0, 3.31.1, 3.32.0, 3.32.1, 3.33.0, 3.33.1, 3.34.0, 3.34.1, 3.35.0, 3.36.0, 3.37.0, 3.37.1, 3.37.2, 3.37.3, 3.38.0, 3.38.1, 3.39.0, 3.40.0, 3.40.1, 3.41.0, 3.41.1, 3.42.0, 3.43.0, 3.44.0, 3.45.0, 3.45.1, 3.46.0, 3.47.0, 3.47.1, 3.48.0, 3.49.0, 3.50.0, 3.51.0, 3.52.0, 3.53.0, 3.53.1, 3.54.0, 3.54.1, 3.55.0, 3.56.0, 3.57.0, 3.57.1, 3.58.0, 3.58.1, 3.59.0, 3.60.0, 3.61.0, 3.62.0, 3.63.0, 3.64.0, 3.65.0, 3.66.0, 3.67.0, 3.67.1, 3.68.0, 3.68.1, 3.69.0, 3.70.0, 3.70.1, 3.71.0, 3.72.0, 3.73.0, 3.74.0, 3.75.0, 3.75.1, 3.76.0, 3.76.1, 3.77.0, 3.77.1, 3.77.2, 3.78.0, 3.78.1, 3.78.2, 3.78.3, 3.79.0, 3.79.1, 3.80.0, 3.81.0, 3.81.1, 3.82.0, 3.82.1, 3.83.0, 3.83.1, 3.83.2, 3.84.0, 3.84.1, 3.84.2, 3.85.0, 3.85.1, 3.86.0, 3.86.1, 3.86.2, 3.86.3, 3.87.0, 3.87.1, 3.87.2, 3.88.0, 3.88.1, 3.89.0, 3.89.1, 3.90.0, 3.90.1, 3.90.2, 3.90.3, 3.90.4, 3.91.0, 3.91.1, 3.92.0, 3.92.1, 3.92.2, 3.92.3, 3.93.0, 3.93.1, 3.93.2, 3.94.0, 3.94.1. NVD record
Sonatype range
Sonatype: Sonatype Nexus Repository 3 CE/Pro versions 3.16.0 through 3.94.x. Sonatype advisory
CVE-2026-0600 published January 14, 2026

Server-Side Request Forgery (SSRF) vulnerability in Sonatype Nexus Repository 3 versions 3.0.0 and later allows authenticated administrators to configure proxy repositories with URLs that can access unintended network destinations, potentially including cloud metadata services and internal network resources. A workaround configuration is available starting in version 3.88.0, but the product remains vulnerable by default.

Medium6.2 CVSS 4.0 6.2, rated by Sonatype (CNA) no NVD data yes No fixed version published. Sonatype names a workaround from Sonatype Nexus Repository 3.88.0 (CE/Pro). Latest: 3.96.2.
Sources for CVE-2026-0600 and 3.77.2
NVD range
NVD has published no version configuration for this record (NVD status: Deferred). NVD record
Sonatype range
Sonatype: Sonatype Nexus Repository 3.0.0 and later (CE/Pro). Sonatype advisory
CVE-2026-3438 published April 8, 2026

A reflected cross-site scripting vulnerability exists in Sonatype Nexus Repository versions 3.0.0 through 3.90.2 that allows unauthenticated remote attackers to execute arbitrary JavaScript in a victim's browser through a specially crafted URL. Exploitation requires user interaction.

Medium6.1 CVSS 3.1 6.1, rated by NVD yes yes No fix on your branch; the nearest fix is 3.91.0. Latest: 3.96.2.
Sources for CVE-2026-3438 and 3.77.2
NVD range
NVD configuration (NVD status: Analyzed): from 3.0.0 (including), before 3.91.0. NVD record
Sonatype range
Sonatype: All Sonatype Nexus Repository 3.x CE/Pro versions up to and including 3.90.x. Sonatype advisory
CVE-2026-77123 published September 2, 2026

Nexus Repository 3 contains a sensitive information disclosure vulnerability in the capability read API. An account holding the nexus:capabilities:read privilege can retrieve the plaintext shared secret configured on a webhook capability, which is intended to be masked from all API responses. This issue affects Nexus Repository 3 versions 3.2.0 through 3.95.x, and is fixed in version 3.96.0.

Medium6.0 CVSS 4.0 6.0, rated by Sonatype (CNA) yes yes No fix on your branch; the nearest fix is 3.96.0. Latest: 3.96.2.
Sources for CVE-2026-77123 and 3.77.2
NVD range
NVD indexes 171 exact versions from the CNA's CPE list (NVD status: Undergoing Analysis): 3.2.0, 3.2.1, 3.3.0, 3.3.1, 3.3.2, 3.4.0, 3.5.0, 3.5.1, 3.5.2, 3.6.0, 3.6.1, 3.6.2, 3.7.0, 3.7.1, 3.8.0, 3.9.0, 3.10.0, 3.11.0, 3.12.0, 3.12.1, 3.13.0, 3.14.0, 3.15.0, 3.15.1, 3.15.2, 3.16.0, 3.16.1, 3.16.2, 3.17.0, 3.18.0, 3.18.1, 3.19.0, 3.19.1, 3.20.0, 3.20.1, 3.21.0, 3.21.1, 3.21.2, 3.22.0, 3.22.1, 3.23.0, 3.24.0, 3.25.0, 3.25.1, 3.26.0, 3.26.1, 3.27.0, 3.28.0, 3.28.1, 3.29.0, 3.29.2, 3.30.0, 3.30.1, 3.31.0, 3.31.1, 3.32.0, 3.32.1, 3.33.0, 3.33.1, 3.34.0, 3.34.1, 3.35.0, 3.36.0, 3.37.0, 3.37.1, 3.37.2, 3.37.3, 3.38.0, 3.38.1, 3.39.0, 3.40.0, 3.40.1, 3.41.0, 3.41.1, 3.42.0, 3.43.0, 3.44.0, 3.45.0, 3.45.1, 3.46.0, 3.47.1, 3.48.0, 3.49.0, 3.50.0, 3.51.0, 3.52.0, 3.53.0, 3.53.1, 3.54.0, 3.54.1, 3.55.0, 3.56.0, 3.57.1, 3.58.1, 3.59.0, 3.60.0, 3.61.0, 3.62.0, 3.63.0, 3.64.0, 3.65.0, 3.66.0, 3.67.1, 3.68.0, 3.68.1, 3.69.0, 3.70.0, 3.70.1, 3.70.2, 3.70.3, 3.70.4, 3.70.5, 3.71.0, 3.72.0, 3.73.0, 3.74.0, 3.75.0, 3.75.1, 3.76.0, 3.76.1, 3.77.0, 3.77.1, 3.77.2, 3.78.0, 3.78.1, 3.78.2, 3.78.3, 3.79.0, 3.79.1, 3.80.0, 3.81.0, 3.81.1, 3.82.0, 3.82.1, 3.83.0, 3.83.1, 3.83.2, 3.84.0, 3.84.1, 3.84.2, 3.85.0, 3.85.1, 3.86.0, 3.86.2, 3.86.3, 3.87.0, 3.87.1, 3.87.2, 3.88.0, 3.89.0, 3.89.1, 3.90.0, 3.90.1, 3.90.2, 3.90.3, 3.90.4, 3.90.5, 3.91.0, 3.91.1, 3.92.0, 3.92.1, 3.92.2, 3.92.3, 3.93.0, 3.93.1, 3.93.2, 3.94.0, 3.94.1, 3.95.0, 3.95.1, 3.95.2. NVD record
Sonatype range
Sonatype: All Sonatype Nexus Repository 3 CE/Pro versions from 3.2.0 up to and including 3.95.x. Sonatype advisory
CVE-2026-17595 published August 7, 2026

Nexus Repository 3 did not fully sandbox JEXL expressions used in Content Selectors. An account holding the nexus:selectors:create permission could construct an expression that read Java object properties not intended to be exposed to the expression engine, disclosing internal JVM class metadata such as class and classloader names. This issue does not permit method invocation, object construction, or arbitrary code execution. This has been fixed by restricting property access in the JEXL sandbox to the intended data types.

Medium5.3 CVSS 4.0 5.3, rated by Sonatype (CNA) yes yes No fix on your branch; the nearest fix is 3.95.0. Latest: 3.96.2.
Sources for CVE-2026-17595 and 3.77.2
NVD range
NVD indexes 154 exact versions from the CNA's CPE list (NVD status: Undergoing Analysis): 3.15.0, 3.15.1, 3.15.2, 3.15.3, 3.16.0, 3.16.1, 3.16.2, 3.17.0, 3.17.1, 3.17.2, 3.18.0, 3.18.1, 3.19.0, 3.19.1, 3.20.0, 3.20.1, 3.20.2, 3.20.3, 3.21.0, 3.21.1, 3.21.2, 3.22.0, 3.22.1, 3.23.0, 3.24.0, 3.24.1, 3.25.0, 3.25.1, 3.26.0, 3.26.1, 3.27.0, 3.28.0, 3.28.1, 3.29.0, 3.29.1, 3.29.2, 3.30.0, 3.30.1, 3.31.0, 3.31.1, 3.32.0, 3.32.1, 3.33.0, 3.33.1, 3.34.0, 3.34.1, 3.35.0, 3.36.0, 3.37.0, 3.37.1, 3.37.2, 3.37.3, 3.38.0, 3.38.1, 3.39.0, 3.40.0, 3.40.1, 3.41.0, 3.41.1, 3.42.0, 3.43.0, 3.44.0, 3.45.0, 3.45.1, 3.46.0, 3.47.0, 3.47.1, 3.48.0, 3.49.0, 3.50.0, 3.51.0, 3.52.0, 3.53.0, 3.53.1, 3.54.0, 3.54.1, 3.55.0, 3.56.0, 3.57.0, 3.57.1, 3.58.0, 3.58.1, 3.59.0, 3.60.0, 3.61.0, 3.62.0, 3.63.0, 3.64.0, 3.65.0, 3.66.0, 3.67.0, 3.67.1, 3.68.0, 3.68.1, 3.69.0, 3.70.0, 3.70.1, 3.71.0, 3.72.0, 3.73.0, 3.74.0, 3.75.0, 3.75.1, 3.76.0, 3.76.1, 3.77.0, 3.77.1, 3.77.2, 3.78.0, 3.78.1, 3.78.2, 3.78.3, 3.79.0, 3.79.1, 3.80.0, 3.81.0, 3.81.1, 3.82.0, 3.82.1, 3.83.0, 3.83.1, 3.83.2, 3.84.0, 3.84.1, 3.84.2, 3.85.0, 3.85.1, 3.86.0, 3.86.1, 3.86.2, 3.86.3, 3.87.0, 3.87.1, 3.87.2, 3.88.0, 3.88.1, 3.89.0, 3.89.1, 3.90.0, 3.90.1, 3.90.2, 3.90.3, 3.90.4, 3.91.0, 3.91.1, 3.92.0, 3.92.1, 3.92.2, 3.92.3, 3.93.0, 3.93.1, 3.93.2, 3.94.0, 3.94.1. NVD record
Sonatype range
Sonatype: All previous Sonatype Nexus Repository 3 CE/Pro versions from 3.15.0 up to and including 3.94.x. Sonatype advisory
CVE-2026-7494 published July 14, 2026

Nexus Repository 3 is vulnerable to Server-Side Request Forgery (SSRF) via the SSL Certificate Retrieval endpoint. A user holding the nexus:ssl-truststore:read permission could cause the server to initiate outbound connections to internal or otherwise restricted network hosts. This issue affects Nexus Repository 3.0.0 through versions prior to 3.94.0.

Medium5.3 CVSS 4.0 5.3, rated by Sonatype (CNA) no NVD data yes No fix on your branch; the nearest fix is 3.94.0. Latest: 3.96.2.
Sources for CVE-2026-7494 and 3.77.2
NVD range
NVD has published no version configuration for this record (NVD status: Undergoing Analysis). NVD record
Sonatype range
Sonatype: Sonatype Nexus Repository 3 CE/Pro versions 3.0.0 up to and including 3.93.x. Sonatype advisory
CVE-2026-77121 published September 2, 2026

A user account with permission to deploy artifacts to a hosted Maven repository could upload a POM file containing an oversized metadata field. This causes future attempts to list or browse that repository's components to permanently fail until an administrator repairs the underlying data. Only the targeted repository is affected; other repositories and overall server health remain unaffected.

Medium5.3 CVSS 4.0 5.3, rated by Sonatype (CNA) yes yes No fix on your branch; the nearest fix is 3.95.0. Latest: 3.96.2.
Sources for CVE-2026-77121 and 3.77.2
NVD range
NVD indexes 127 exact versions from the CNA's CPE list (NVD status: Undergoing Analysis): 3.26.0, 3.26.1, 3.27.0, 3.28.0, 3.28.1, 3.29.0, 3.29.1, 3.29.2, 3.30.0, 3.30.1, 3.31.0, 3.31.1, 3.32.0, 3.32.1, 3.33.0, 3.33.1, 3.34.0, 3.34.1, 3.35.0, 3.36.0, 3.37.0, 3.37.1, 3.37.2, 3.37.3, 3.38.0, 3.38.1, 3.39.0, 3.40.0, 3.40.1, 3.41.0, 3.41.1, 3.42.0, 3.43.0, 3.44.0, 3.45.0, 3.45.1, 3.46.0, 3.47.0, 3.47.1, 3.48.0, 3.49.0, 3.50.0, 3.51.0, 3.52.0, 3.53.0, 3.53.1, 3.54.0, 3.54.1, 3.55.0, 3.56.0, 3.57.0, 3.57.1, 3.58.0, 3.58.1, 3.59.0, 3.60.0, 3.61.0, 3.62.0, 3.63.0, 3.64.0, 3.65.0, 3.66.0, 3.67.0, 3.67.1, 3.68.0, 3.68.1, 3.69.0, 3.70.0, 3.70.1, 3.71.0, 3.72.0, 3.73.0, 3.74.0, 3.75.0, 3.75.1, 3.76.0, 3.76.1, 3.77.0, 3.77.1, 3.77.2, 3.78.0, 3.78.1, 3.78.2, 3.78.3, 3.79.0, 3.79.1, 3.80.0, 3.81.0, 3.81.1, 3.82.0, 3.82.1, 3.83.0, 3.83.1, 3.83.2, 3.84.0, 3.84.1, 3.84.2, 3.85.0, 3.85.1, 3.86.0, 3.86.1, 3.86.2, 3.86.3, 3.87.0, 3.87.1, 3.87.2, 3.88.0, 3.88.1, 3.89.0, 3.89.1, 3.90.0, 3.90.1, 3.90.2, 3.90.3, 3.90.4, 3.90.5, 3.91.0, 3.91.1, 3.92.0, 3.92.1, 3.92.2, 3.92.3, 3.93.0, 3.93.1, 3.93.2, 3.94.0, 3.94.1. NVD record
Sonatype range
Sonatype: Nexus Repository 3 CE/Pro versions 3.26 through 3.94.x. Sonatype advisory
CVE-2026-77122 published September 2, 2026

An authorization flaw in the REST API repository details endpoint (GET /service/rest/v1/repositories/{repositoryName}) in Sonatype Nexus Repository 3 allowed an account holding read or browse permission on a group repository to retrieve metadata for member repositories on which it held no direct permission, by requesting the endpoint directly for the member repository name. For proxy repositories, the disclosed metadata includes the configured remote URL, which may reveal internal upstream hostnames. This includes the anonymous user if it has been granted this permission; whether the anonymous user holds this permission depends on the role and permission configuration of the specific installation.

Medium5.3 CVSS 4.0 5.3, rated by Sonatype (CNA) yes yes No fix on your branch; the nearest fix is 3.96.0. Latest: 3.96.2.
Sources for CVE-2026-77122 and 3.77.2
NVD range
NVD indexes 105 exact versions from the CNA's CPE list (NVD status: Undergoing Analysis): 3.38.0, 3.38.1, 3.39.0, 3.40.0, 3.40.1, 3.41.0, 3.41.1, 3.42.0, 3.43.0, 3.44.0, 3.45.0, 3.45.1, 3.46.0, 3.47.1, 3.48.0, 3.49.0, 3.50.0, 3.51.0, 3.52.0, 3.53.0, 3.53.1, 3.54.0, 3.54.1, 3.55.0, 3.56.0, 3.57.1, 3.58.1, 3.59.0, 3.60.0, 3.61.0, 3.62.0, 3.63.0, 3.64.0, 3.65.0, 3.66.0, 3.67.1, 3.68.0, 3.68.1, 3.69.0, 3.70.0, 3.70.1, 3.70.2, 3.70.3, 3.70.4, 3.70.5, 3.71.0, 3.72.0, 3.73.0, 3.74.0, 3.75.0, 3.75.1, 3.76.0, 3.76.1, 3.77.0, 3.77.1, 3.77.2, 3.78.0, 3.78.1, 3.78.2, 3.78.3, 3.79.0, 3.79.1, 3.80.0, 3.81.0, 3.81.1, 3.82.0, 3.82.1, 3.83.0, 3.83.1, 3.83.2, 3.84.0, 3.84.1, 3.84.2, 3.85.0, 3.85.1, 3.86.0, 3.86.2, 3.86.3, 3.87.0, 3.87.1, 3.87.2, 3.88.0, 3.89.0, 3.89.1, 3.90.0, 3.90.1, 3.90.2, 3.90.3, 3.90.4, 3.90.5, 3.91.0, 3.91.1, 3.92.0, 3.92.1, 3.92.2, 3.92.3, 3.93.0, 3.93.1, 3.93.2, 3.94.0, 3.94.1, 3.95.0, 3.95.1, 3.95.2, 3.95.3. NVD record
Sonatype range
Sonatype: All Sonatype Nexus Repository 3 CE/Pro versions from 3.38.0 up to (but not including) 3.96.0. Sonatype advisory
CVE-2026-14645 published July 14, 2026

Nexus Repository 3 does not validate the destination of the "Webhook: Global" capability's configured URL before making an outbound HTTP request, allowing a user holding the Capability Administration permission to cause the server to send requests to internal network locations (Server-Side Request Forgery). This permission is granted by role assignment, independent of authentication status, so an unauthenticated user could also trigger this behavior if the anonymous role has been granted the permission.

Medium5.1 CVSS 4.0 5.1, rated by Sonatype (CNA) no NVD data yes No fix on your branch; the nearest fix is 3.94.0. Latest: 3.96.2.
Sources for CVE-2026-14645 and 3.77.2
NVD range
NVD has published no version configuration for this record (NVD status: Undergoing Analysis). NVD record
Sonatype range
Sonatype: All previous Sonatype Nexus Repository 3 CE/Pro versions up to and including 3.93.x. Sonatype advisory
CVE-2026-17597 published August 7, 2026

Nexus Repository 3 contains a Server-Side Request Forgery (SSRF) vulnerability in the email configuration verification feature. A user holding the nexus:settings:update permission could submit arbitrary host and port values to the email test/verification endpoint, causing the server to attempt outbound network connections to internal or otherwise restricted network addresses. Differences in the server's response could be used to infer whether internal hosts and ports are reachable. This issue affects Nexus Repository 3 CE/Pro versions up to and including 3.94.1, and is fixed in version 3.95.0.

Medium5.1 CVSS 4.0 5.1, rated by Sonatype (CNA) yes yes No fix on your branch; the nearest fix is 3.95.0. Latest: 3.96.2.
Sources for CVE-2026-17597 and 3.77.2
NVD range
NVD indexes 180 exact versions from the CNA's CPE list (NVD status: Undergoing Analysis): 3.0.0, 3.0.1, 3.0.2, 3.1.0, 3.2.0, 3.2.1, 3.3.0, 3.3.1, 3.3.2, 3.4.0, 3.5.0, 3.5.1, 3.5.2, 3.6.0, 3.6.1, 3.6.2, 3.7.0, 3.7.1, 3.8.0, 3.9.0, 3.10.0, 3.11.0, 3.12.0, 3.12.1, 3.13.0, 3.14.0, 3.15.0, 3.15.1, 3.15.2, 3.15.3, 3.16.0, 3.16.1, 3.16.2, 3.17.0, 3.17.1, 3.17.2, 3.18.0, 3.18.1, 3.19.0, 3.19.1, 3.20.0, 3.20.1, 3.20.2, 3.20.3, 3.21.0, 3.21.1, 3.21.2, 3.22.0, 3.22.1, 3.23.0, 3.24.0, 3.24.1, 3.25.0, 3.25.1, 3.26.0, 3.26.1, 3.27.0, 3.28.0, 3.28.1, 3.29.0, 3.29.1, 3.29.2, 3.30.0, 3.30.1, 3.31.0, 3.31.1, 3.32.0, 3.32.1, 3.33.0, 3.33.1, 3.34.0, 3.34.1, 3.35.0, 3.36.0, 3.37.0, 3.37.1, 3.37.2, 3.37.3, 3.38.0, 3.38.1, 3.39.0, 3.40.0, 3.40.1, 3.41.0, 3.41.1, 3.42.0, 3.43.0, 3.44.0, 3.45.0, 3.45.1, 3.46.0, 3.47.0, 3.47.1, 3.48.0, 3.49.0, 3.50.0, 3.51.0, 3.52.0, 3.53.0, 3.53.1, 3.54.0, 3.54.1, 3.55.0, 3.56.0, 3.57.0, 3.57.1, 3.58.0, 3.58.1, 3.59.0, 3.60.0, 3.61.0, 3.62.0, 3.63.0, 3.64.0, 3.65.0, 3.66.0, 3.67.0, 3.67.1, 3.68.0, 3.68.1, 3.69.0, 3.70.0, 3.70.1, 3.71.0, 3.72.0, 3.73.0, 3.74.0, 3.75.0, 3.75.1, 3.76.0, 3.76.1, 3.77.0, 3.77.1, 3.77.2, 3.78.0, 3.78.1, 3.78.2, 3.78.3, 3.79.0, 3.79.1, 3.80.0, 3.81.0, 3.81.1, 3.82.0, 3.82.1, 3.83.0, 3.83.1, 3.83.2, 3.84.0, 3.84.1, 3.84.2, 3.85.0, 3.85.1, 3.86.0, 3.86.1, 3.86.2, 3.86.3, 3.87.0, 3.87.1, 3.87.2, 3.88.0, 3.88.1, 3.89.0, 3.89.1, 3.90.0, 3.90.1, 3.90.2, 3.90.3, 3.90.4, 3.91.0, 3.91.1, 3.92.0, 3.92.1, 3.92.2, 3.92.3, 3.93.0, 3.93.1, 3.93.2, 3.94.0, 3.94.1. NVD record
Sonatype range
Sonatype: All previous Sonatype Nexus Repository 3 CE/Pro versions up to and including 3.94.x. Sonatype advisory
CVE-2026-3048 published May 11, 2026

An authenticated administrator who configures or tests LDAP connectivity in Sonatype Nexus Repository Manager versions 3.0.0 through 3.91.1 may be able to initiate unintended server-side connections when interacting with a malicious LDAP server.

Medium5.1 CVSS 4.0 5.1, rated by Sonatype (CNA) no yes No fix on your branch; the nearest fix is 3.92.0. Latest: 3.96.2.
Sources for CVE-2026-3048 and 3.77.2
NVD range
NVD indexes 158 exact versions from the CNA's CPE list (NVD status: Undergoing Analysis): 3.0.0, 3.0.1, 3.0.2, 3.1.0, 3.2.0, 3.2.1, 3.3.0, 3.3.1, 3.3.2, 3.4.0, 3.5.0, 3.5.1, 3.5.2, 3.6.0, 3.6.1, 3.6.2, 3.7.0, 3.7.1, 3.8.0, 3.9.0, 3.10.0, 3.11.0, 3.12.0, 3.12.1, 3.13.0, 3.14.0, 3.15.0, 3.15.1, 3.15.2, 3.16.0, 3.16.1, 3.16.2, 3.17.0, 3.18.0, 3.18.1, 3.19.0, 3.19.1, 3.20.0, 3.20.1, 3.21.0, 3.21.1, 3.21.2, 3.22.0, 3.22.1, 3.23.0, 3.24.0, 3.25.0, 3.25.1, 3.26.0, 3.26.1, 3.27.0, 3.28.0, 3.28.1, 3.29.0, 3.29.2, 3.30.0, 3.30.1, 3.31.0, 3.31.1, 3.32.0, 3.32.1, 3.33.0, 3.33.1, 3.34.0, 3.34.1, 3.35.0, 3.36.0, 3.37.0, 3.37.1, 3.37.2, 3.37.3, 3.38.0, 3.38.1, 3.39.0, 3.40.0, 3.40.1, 3.41.0, 3.41.1, 3.42.0, 3.43.0, 3.44.0, 3.45.0, 3.45.1, 3.46.0, 3.47.0, 3.47.1, 3.48.0, 3.49.0, 3.50.0, 3.51.0, 3.52.0, 3.53.0, 3.53.1, 3.54.0, 3.54.1, 3.55.0, 3.56.0, 3.57.0, 3.57.1, 3.58.0, 3.58.1, 3.59.0, 3.60.0, 3.61.0, 3.62.0, 3.63.0, 3.64.0, 3.65.0, 3.66.0, 3.67.0, 3.67.1, 3.68.0, 3.68.1, 3.69.0, 3.70.0, 3.70.1, 3.70.2, 3.70.3, 3.70.4, 3.70.5, 3.71.0, 3.72.0, 3.73.0, 3.74.0, 3.75.0, 3.75.1, 3.76.0, 3.76.1, 3.77.0, 3.78.0, 3.78.1, 3.79.0, 3.80.0, 3.81.0, 3.82.0, 3.83.0, 3.83.1, 3.83.2, 3.84.0, 3.84.1, 3.84.2, 3.85.0, 3.85.1, 3.86.0, 3.86.2, 3.86.3, 3.87.0, 3.87.1, 3.87.2, 3.88.0, 3.89.0, 3.89.1, 3.90.0, 3.90.1, 3.90.2, 3.90.3, 3.91.0, 3.91.1. NVD record
Sonatype range
Sonatype: Sonatype Nexus Repository 3.0.0 through 3.91.x (CE/Pro). Sonatype advisory
CVE-2026-7308 published May 11, 2026

An authenticated user with upload permission to a hosted repository can store content that causes arbitrary JavaScript to execute in the browser of any user who browses that repository directory via the HTML index page in Sonatype Nexus Repository versions 3.6.0 through versions before 3.92.0. This could allow the attacker to perform actions in the context of the victim's session.

Medium5.1 CVSS 4.0 5.1, rated by Sonatype (CNA) no NVD data yes No fix on your branch; the nearest fix is 3.92.0. Latest: 3.96.2.
Sources for CVE-2026-7308 and 3.77.2
NVD range
NVD has published no version configuration for this record (NVD status: Undergoing Analysis). NVD record
Sonatype range
Sonatype: Sonatype Nexus Repository 3.6.0 through 3.91.x (CE/Pro). Sonatype advisory
CVE-2026-10741 published June 17, 2026

Sonatype Nexus Repository Manager before 3.93.0 contains an authorization vulnerability in the proxy repository configuration that allows a delegated repository administrator to disclose stored upstream proxy credentials.

Medium4.9 CVSS 3.1 4.9, rated by NVD yes yes No fix on your branch; the nearest fix is 3.93.0. Latest: 3.96.2.
Sources for CVE-2026-10741 and 3.77.2
NVD range
NVD configuration (NVD status: Analyzed): from 3.1.0 (including), before 3.93.0. NVD record
Sonatype range
Sonatype: All Sonatype Nexus Repository 3.x versions from 3.1.0 through 3.92.x. Sonatype advisory
CVE-2026-14646 published July 14, 2026

Nexus Repository 3 did not apply its existing Server-Side Request Forgery (SSRF) protections to HTTP redirect targets returned by proxy repository upstream servers. Any user with read access to a proxy repository backed by an attacker-controlled or compromised upstream server - including an anonymous user, if anonymous access is enabled - could receive a response from an internal network address or cloud metadata endpoint as repository content, potentially exposing sensitive information such as cloud IAM credentials.

Medium4.9 CVSS 4.0 4.9, rated by Sonatype (CNA) no yes No fix on your branch; the nearest fix is 3.94.0. Latest: 3.96.2.
Sources for CVE-2026-14646 and 3.77.2
NVD range
NVD indexes 165 exact versions from the CNA's CPE list (NVD status: Undergoing Analysis): 3.0.0, 3.0.1, 3.0.2, 3.1.0, 3.2.0, 3.2.1, 3.3.0, 3.3.1, 3.3.2, 3.4.0, 3.5.0, 3.5.1, 3.5.2, 3.6.0, 3.6.1, 3.6.2, 3.7.0, 3.7.1, 3.8.0, 3.9.0, 3.10.0, 3.11.0, 3.12.0, 3.12.1, 3.13.0, 3.14.0, 3.15.0, 3.15.1, 3.15.2, 3.16.0, 3.16.1, 3.16.2, 3.17.0, 3.18.0, 3.18.1, 3.19.0, 3.19.1, 3.20.0, 3.20.1, 3.21.0, 3.21.1, 3.21.2, 3.22.0, 3.22.1, 3.23.0, 3.24.0, 3.25.0, 3.25.1, 3.26.0, 3.26.1, 3.27.0, 3.28.0, 3.28.1, 3.29.0, 3.29.2, 3.30.0, 3.30.1, 3.31.0, 3.31.1, 3.32.0, 3.32.1, 3.33.0, 3.33.1, 3.34.0, 3.34.1, 3.35.0, 3.36.0, 3.37.0, 3.37.1, 3.37.2, 3.37.3, 3.38.0, 3.38.1, 3.39.0, 3.40.0, 3.40.1, 3.41.0, 3.41.1, 3.42.0, 3.43.0, 3.44.0, 3.45.0, 3.45.1, 3.46.0, 3.47.0, 3.47.1, 3.48.0, 3.49.0, 3.50.0, 3.51.0, 3.52.0, 3.53.0, 3.53.1, 3.54.0, 3.54.1, 3.55.0, 3.56.0, 3.57.0, 3.57.1, 3.58.0, 3.58.1, 3.59.0, 3.60.0, 3.61.0, 3.62.0, 3.63.0, 3.64.0, 3.65.0, 3.66.0, 3.67.0, 3.67.1, 3.68.0, 3.68.1, 3.69.0, 3.70.0, 3.70.1, 3.70.2, 3.70.3, 3.70.4, 3.70.5, 3.71.0, 3.72.0, 3.73.0, 3.74.0, 3.75.0, 3.75.1, 3.76.0, 3.76.1, 3.77.0, 3.78.0, 3.78.1, 3.79.0, 3.80.0, 3.81.0, 3.82.0, 3.83.0, 3.83.1, 3.83.2, 3.84.0, 3.84.1, 3.84.2, 3.85.0, 3.85.1, 3.86.0, 3.86.2, 3.86.3, 3.87.0, 3.87.1, 3.87.2, 3.88.0, 3.89.0, 3.89.1, 3.90.0, 3.90.1, 3.90.2, 3.90.3, 3.91.0, 3.91.1, 3.92.0, 3.92.1, 3.92.2, 3.92.3, 3.93.0, 3.93.1, 3.93.2. NVD record
Sonatype range
Sonatype: All Sonatype Nexus Repository 3 CE/Pro versions from 3.0.0 up to and including 3.93.x. Sonatype advisory
39 other Sonatype Nexus Repository CVEs on record that do not affect 3.77.2

Each of these is fixed at or before 3.77.2 on its branch, or its published range does not include this version. The fix column shows the fix this version already carries.

Sonatype Nexus Repository CVEs on record that do not affect 3.77.2
CVE-2019-7238 published March 21, 2019 Critical9.8 CVSS 3.1 9.8, rated by NVD no no Sonatype CNA range No Sonatype CNA range for this CVE (assigned by MITRE); NVD's published range does not include this version.
Sources for CVE-2019-7238 and 3.77.2
NVD range
NVD configuration (NVD status: Analyzed): from 3.0.0 (including), before 3.15.0. NVD record
Sonatype range
Sonatype publishes no affected range in the CVE record (assigned by MITRE). Sonatype advisory
CVE-2019-9629 published July 8, 2019 Critical9.8 CVSS 3.0 9.8, rated by NVD no no Sonatype CNA range No Sonatype CNA range for this CVE (assigned by MITRE); NVD's published range does not include this version.
Sources for CVE-2019-9629 and 3.77.2
NVD range
NVD configuration (NVD status: Modified): before 3.17.0. NVD record
Sonatype range
Sonatype publishes no affected range in the CVE record (assigned by MITRE). Sonatype advisory
CVE-2026-5189 published April 15, 2026 Critical9.8 CVSS 3.1 9.8, rated by NVD no no This version is outside the affected range.
Sources for CVE-2026-5189 and 3.77.2
NVD range
NVD configuration (NVD status: Analyzed): from 3.0.0 (including), before 3.71.0. NVD record
Sonatype range
Sonatype: All Sonatype Nexus Repository 3.x CE/Pro versions 3.0.0 through 3.70.5. Sonatype advisory
CVE-2020-10199 published April 1, 2020 High8.8 CVSS 3.1 8.8, rated by NVD no no This version is outside the affected range.
Sources for CVE-2020-10199 and 3.77.2
NVD range
NVD configuration (NVD status: Analyzed): before 3.21.2. NVD record
Sonatype range
Sonatype: All previous Nexus Repository 3.x OSS/Pro versions up to and including 3.21.1. Sonatype advisory
CVE-2020-11444 published April 2, 2020 High8.8 CVSS 3.1 8.8, rated by NVD no no This version is outside the affected range.
Sources for CVE-2020-11444 and 3.77.2
NVD range
NVD configuration (NVD status: Modified): from 3.0.0 (including), through 3.21.2. NVD record
Sonatype range
Sonatype: All previous Nexus Repository 3 OSS/Pro versions up to and including 3.21.2. Sonatype advisory
CVE-2020-11753 published April 20, 2020 High8.8 CVSS 3.1 8.8, rated by NVD no no This version is outside the affected range.
Sources for CVE-2020-11753 and 3.77.2
NVD range
NVD configuration (NVD status: Modified): exactly 3.21.1; exactly 3.22.0. NVD record
Sonatype range
Sonatype: Nexus Repository 3 OSS/Pro versions 3.21.1 and 3.22.0. Sonatype advisory
CVE-2020-15871 published July 31, 2020 High8.8 CVSS 3.1 8.8, rated by NVD no no Sonatype CNA range No Sonatype CNA range for this CVE (assigned by MITRE); NVD's published range does not include this version.
Sources for CVE-2020-15871 and 3.77.2
NVD range
NVD configuration (NVD status: Modified): before 3.25.1. NVD record
Sonatype range
Sonatype publishes no affected range in the CVE record (assigned by MITRE). Sonatype advisory
CVE-2021-40143 published September 7, 2021 High8.2 CVSS 3.1 8.2, rated by NVD no no This version is outside the affected range.
Sources for CVE-2021-40143 and 3.77.2
NVD range
NVD configuration (NVD status: Modified): from 3.0.0 (including), before 3.34.0. NVD record
Sonatype range
Sonatype: Nexus Repository 3 versions up to and including 3.33.1. Sonatype advisory
CVE-2026-14504 published July 14, 2026 High8.2 CVSS 4.0 8.2, rated by Sonatype (CNA) no NVD data no This version predates the affected range (from 3.88.0).
Sources for CVE-2026-14504 and 3.77.2
NVD range
NVD has published no version configuration for this record (NVD status: Undergoing Analysis). NVD record
Sonatype range
Sonatype: All previous Sonatype Nexus Repository 3 CE/Pro versions with Terraform hosted repositories (3.88.0+), Swift hosted repositories (3.89.0+), or Conda hosted repositories (3.91.0+), up to and including 3.93.x. Sonatype advisory
CVE-2018-16620 published November 15, 2018 High7.5 CVSS 3.0 7.5, rated by NVD no no This version is outside the affected range.
Sources for CVE-2018-16620 and 3.77.2
NVD range
NVD configuration (NVD status: Modified): before 3.14.0. NVD record
Sonatype range
Sonatype: All previous Nexus Repository 3 OSS/Pro versions up to and including 3.13.0. Sonatype advisory
CVE-2019-9630 published July 8, 2019 High7.5 CVSS 3.0 7.5, rated by NVD no no Sonatype CNA range No Sonatype CNA range for this CVE (assigned by MITRE); NVD's published range does not include this version.
Sources for CVE-2019-9630 and 3.77.2
NVD range
NVD configuration (NVD status: Modified): before 3.17.0. NVD record
Sonatype range
Sonatype publishes no affected range in the CVE record (assigned by MITRE). Sonatype advisory
CVE-2020-15868 published August 12, 2020 High7.5 CVSS 3.1 7.5, rated by NVD no no Sonatype CNA range No Sonatype CNA range for this CVE (assigned by MITRE); NVD's published range does not include this version.
Sources for CVE-2020-15868 and 3.77.2
NVD range
NVD configuration (NVD status: Modified): before 3.26.0. NVD record
Sonatype range
Sonatype publishes no affected range in the CVE record (assigned by MITRE). Sonatype advisory
CVE-2024-4956 published May 16, 2024 High7.5 CVSS 3.1 7.5, rated by Sonatype (CNA) no NVD data no This version is outside the affected range.
Sources for CVE-2024-4956 and 3.77.2
NVD range
NVD has published no version configuration for this record (NVD status: Deferred). NVD record
Sonatype range
Sonatype: All previous Sonatype Nexus Repository 3.x OSS/Pro versions up to and including 3.68.0. Sonatype advisory
CVE-2018-16621 published November 15, 2018 High7.2 CVSS 3.1 7.2, rated by NVD no no This version is outside the affected range.
Sources for CVE-2018-16621 and 3.77.2
NVD range
NVD configuration (NVD status: Modified): before 3.14.0. NVD record
Sonatype range
Sonatype: All previous Nexus Repository 3 OSS/Pro versions up to and including 3.13.0. Sonatype advisory
CVE-2019-16530 published October 21, 2019 High7.2 CVSS 3.1 7.2, rated by NVD no no This version is outside the affected range.
Sources for CVE-2019-16530 and 3.77.2
NVD range
NVD configuration (NVD status: Modified): from 2.0.0 (including), through 2.14.14; from 3.0.0 (including), through 3.18.1. NVD record
Sonatype range
Sonatype: Nexus Repository 2 versions up to and including 2.14.14; Nexus Repository 3 versions up to and including 3.18.1; IQ Server versions up to and including 72. Sonatype advisory
CVE-2020-10204 published April 1, 2020 High7.2 CVSS 3.1 7.2, rated by NVD no no Sonatype CNA range No Sonatype CNA range for this CVE (assigned by MITRE); NVD's published range does not include this version.
Sources for CVE-2020-10204 and 3.77.2
NVD range
NVD configuration (NVD status: Modified): before 3.21.2. NVD record
Sonatype range
Sonatype publishes no affected range in the CVE record (assigned by MITRE). Sonatype advisory
CVE-2020-29436 published December 17, 2020 Medium6.5 CVSS 3.1 6.5, rated by NVD no no Sonatype CNA range No Sonatype CNA range for this CVE (assigned by MITRE); NVD's published range does not include this version.
Sources for CVE-2020-29436 and 3.77.2
NVD range
NVD configuration (NVD status: Modified): from 3.0.0 (including), before 3.29.0. NVD record
Sonatype range
Sonatype publishes no affected range in the CVE record (assigned by MITRE). Sonatype advisory
CVE-2024-5764 published October 23, 2024 Medium6.5 CVSS 3.1 6.5, rated by NVD no no This version is outside the affected range.
Sources for CVE-2024-5764 and 3.77.2
NVD range
NVD configuration (NVD status: Analyzed): from 3.0.0 (including), before 3.73.0. NVD record
Sonatype range
Sonatype: All previous Sonatype Nexus Repository Manager 3.x OSS/Pro versions up to and including 3.72.0. Sonatype advisory
CVE-2018-16619 published November 15, 2018 Medium6.1 CVSS 3.0 6.1, rated by NVD no no This version is outside the affected range.
Sources for CVE-2018-16619 and 3.77.2
NVD range
NVD configuration (NVD status: Modified): before 3.14.0. NVD record
Sonatype range
Sonatype: All previous Nexus Repository Manager 3 OSS/Pro versions up to and including 3.13.0. Sonatype advisory
CVE-2018-5306 published February 9, 2018 Medium6.1 CVSS 3.0 6.1, rated by NVD no no This version is outside the affected range.
Sources for CVE-2018-5306 and 3.77.2
NVD range
NVD configuration (NVD status: Modified): from 3.0 (including), before 3.8. NVD record
Sonatype range
Sonatype: All previous 3.x Nexus Repository OSS/Pro versions up to and including 3.7.1. Sonatype advisory
CVE-2020-15870 published July 31, 2020 Medium6.1 CVSS 3.1 6.1, rated by NVD no no This version is outside the affected range.
Sources for CVE-2020-15870 and 3.77.2
NVD range
NVD configuration (NVD status: Modified): before 3.25.1. NVD record
Sonatype range
Sonatype: All previous Nexus Repository 3 OSS/Pro versions up to and including 3.25.0. Sonatype advisory
CVE-2021-29159 published April 28, 2021 Medium6.1 CVSS 3.1 6.1, rated by NVD no no This version is outside the affected range.
Sources for CVE-2021-29159 and 3.77.2
NVD range
NVD configuration (NVD status: Modified): from 3.23.0 (including), before 3.30.1. NVD record
Sonatype range
Sonatype: All Nexus Repository Manager 3 OSS/Pro versions between 3.23 and 3.30. Sonatype advisory
CVE-2019-14469 published August 22, 2019 Medium5.4 CVSS 3.0 5.4, rated by NVD no no This version is outside the affected range.
Sources for CVE-2019-14469 and 3.77.2
NVD range
NVD configuration (NVD status: Modified): from 3.14.0 (including), through 3.17.0. NVD record
Sonatype range
Sonatype: Nexus Repository 3 versions starting in 3.14.0 up to and including 3.17.0. Sonatype advisory
CVE-2020-15869 published July 31, 2020 Medium5.4 CVSS 3.1 5.4, rated by NVD no no This version is outside the affected range.
Sources for CVE-2020-15869 and 3.77.2
NVD range
NVD configuration (NVD status: Modified): before 3.25.1. NVD record
Sonatype range
Sonatype: All previous Nexus Repository Manager 3 OSS/Pro versions up to and including 3.25.0. Sonatype advisory
CVE-2021-37152 published August 10, 2021 Medium5.4 CVSS 3.1 5.4, rated by NVD no no This version is outside the affected range.
Sources for CVE-2021-37152 and 3.77.2
NVD range
NVD configuration (NVD status: Modified): from 3.0.0 (including), before 3.33.0. NVD record
Sonatype range
Sonatype: Nexus Repository 3 versions up to and including 3.32.0. Sonatype advisory
CVE-2021-30635 published April 27, 2021 Medium5.3 CVSS 3.1 5.3, rated by NVD no no This version is outside the affected range.
Sources for CVE-2021-30635 and 3.77.2
NVD range
NVD configuration (NVD status: Modified): from 3.0 (including), before 3.30.1. NVD record
Sonatype range
Sonatype: Nexus Repository Manager 3 versions up to and including 3.30.0. Sonatype advisory
CVE-2026-17598 published August 7, 2026 Medium5.3 CVSS 4.0 5.3, rated by Sonatype (CNA) no no This version predates the affected range (from 3.91.0).
Sources for CVE-2026-17598 and 3.77.2
NVD range
NVD indexes 11 exact versions from the CNA's CPE list (NVD status: Undergoing Analysis): 3.91.0, 3.91.1, 3.92.0, 3.92.1, 3.92.2, 3.92.3, 3.93.0, 3.93.1, 3.93.2, 3.94.0, 3.94.1. NVD record
Sonatype range
Sonatype: Sonatype Nexus Repository 3 CE/Pro versions 3.91.0 through 3.94.x. Sonatype advisory
CVE-2025-13488 published December 4, 2025 Medium5.1 CVSS 4.0 5.1, rated by Sonatype (CNA) no NVD data no This version predates the affected range (from 3.83.0).
Sources for CVE-2025-13488 and 3.77.2
NVD range
NVD has published no version configuration for this record (NVD status: Deferred). NVD record
Sonatype range
Sonatype: Sonatype Nexus Repository 3.x CE/Pro versions 3.83.0 through 3.86.2. Sonatype advisory
CVE-2026-0601 published January 14, 2026 Medium5.1 CVSS 4.0 5.1, rated by Sonatype (CNA) no NVD data no This version predates the affected range (from 3.82.0).
Sources for CVE-2026-0601 and 3.77.2
NVD range
NVD has published no version configuration for this record (NVD status: Deferred). NVD record
Sonatype range
Sonatype: Sonatype Nexus Repository 3.82.0 through 3.87.1 (CE/Pro). Sonatype advisory
CVE-2020-11415 published April 27, 2020 Medium4.9 CVSS 3.1 4.9, rated by NVD no no Sonatype CNA range No Sonatype CNA range for this CVE (assigned by MITRE); NVD's published range does not include this version.
Sources for CVE-2020-11415 and 3.77.2
NVD range
NVD configuration (NVD status: Modified): from 2.0 (including), before 2.14.17; from 3.0 (including), before 3.22.1. NVD record
Sonatype range
Sonatype publishes no affected range in the CVE record (assigned by MITRE). Sonatype advisory
CVE-2020-24622 published August 25, 2020 Medium4.9 CVSS 3.1 4.9, rated by NVD no no This version is outside the affected range.
Sources for CVE-2020-24622 and 3.77.2
NVD range
NVD configuration (NVD status: Modified): from 3.0.0 (including), before 3.27.0. NVD record
Sonatype range
Sonatype: Nexus Repository 3 versions up to and including 3.26.1. Sonatype advisory
CVE-2021-29158 published April 23, 2021 Medium4.9 CVSS 3.1 4.9, rated by NVD no no This version is outside the affected range.
Sources for CVE-2021-29158 and 3.77.2
NVD range
NVD configuration (NVD status: Modified): through 3.30.0. NVD record
Sonatype range
Sonatype: Nexus Repository Manager 3 Pro versions up to and including 3.30.0. Sonatype advisory
CVE-2018-12100 published June 11, 2018 Medium4.8 CVSS 3.0 4.8, rated by NVD no no This version is outside the affected range.
Sources for CVE-2018-12100 and 3.77.2
NVD range
NVD configuration (NVD status: Modified): from 3.3.0 (including), before 3.12.0. NVD record
Sonatype range
Sonatype: All previous Nexus Repository 3 OSS/Pro versions up to and including 3.11.0-01.. Sonatype advisory
CVE-2020-10203 published April 1, 2020 Medium4.8 CVSS 3.1 4.8, rated by NVD no no Sonatype CNA range No Sonatype CNA range for this CVE (assigned by MITRE); NVD's published range does not include this version.
Sources for CVE-2020-10203 and 3.77.2
NVD range
NVD configuration (NVD status: Modified): before 3.21.2. NVD record
Sonatype range
Sonatype publishes no affected range in the CVE record (assigned by MITRE). Sonatype advisory
CVE-2021-34553 published June 18, 2021 Medium4.3 CVSS 3.1 4.3, rated by NVD no no This version is outside the affected range.
Sources for CVE-2021-34553 and 3.77.2
NVD range
NVD configuration (NVD status: Modified): from 3.0.0 (including), before 3.31.0. NVD record
Sonatype range
Sonatype: Nexus Repository 3 versions up to and including 3.30.1. Sonatype advisory
CVE-2021-42568 published November 2, 2021 Medium4.3 CVSS 3.1 4.3, rated by NVD no no Sonatype CNA range No Sonatype CNA range for this CVE (assigned by MITRE); NVD's published range does not include this version.
Sources for CVE-2021-42568 and 3.77.2
NVD range
NVD configuration (NVD status: Modified): from 3.0.0 (including), through 3.35.0. NVD record
Sonatype range
Sonatype publishes no affected range in the CVE record (assigned by MITRE). Sonatype advisory
CVE-2021-43293 published November 4, 2021 Medium4.3 CVSS 3.1 4.3, rated by NVD no no Sonatype CNA range No Sonatype CNA range for this CVE (assigned by MITRE); NVD's published range does not include this version.
Sources for CVE-2021-43293 and 3.77.2
NVD range
NVD configuration (NVD status: Modified): from 3.0.0 (including), through 3.35.0. NVD record
Sonatype range
Sonatype publishes no affected range in the CVE record (assigned by MITRE). Sonatype advisory
CVE-2021-43961 published March 17, 2022 Medium4.3 CVSS 3.1 4.3, rated by NVD no no This version is outside the affected range.
Sources for CVE-2021-43961 and 3.77.2
NVD range
NVD configuration (NVD status: Modified): from 3.0.0 (including), before 3.38.0. NVD record
Sonatype range
Sonatype: Nexus Repository 3 versions up to and including 3.37.3. Sonatype advisory
CVE-2022-27907 published March 30, 2022 Medium4.3 CVSS 3.1 4.3, rated by NVD no no This version is outside the affected range.
Sources for CVE-2022-27907 and 3.77.2
NVD range
NVD configuration (NVD status: Modified): from 3.0.0 (including), before 3.38.0. NVD record
Sonatype range
Sonatype: Nexus Repository 3 versions up to and including 3.37.3. Sonatype advisory

About this page and CloudRepo

CloudRepo is a managed artifact repository, so there is no Artifactory or Nexus server for you to patch. In over 10 years of operation, CloudRepo has experienced no known security breaches. This page is not a scan of your server: the data is NVD's and the vendor's, linked on every row, pulled on September 18, 2026.