Sonatype Nexus Repository 3.95.2: known vulnerabilities
5 known CVEs affect Sonatype Nexus Repository 3.95.2: 4 by NVD's exact CPE match, and 1 more that Sonatype's advisories list and NVD has not analyzed.
NVD's count evaluates NVD's published version ranges against this version; those ranges do not carry Sonatype's per-branch fixes, so the NVD column can read the same on either side of a fix that Sonatype names. Where NVD has not analyzed a record, the row reads "no NVD data", not "no".
- Known CVEs
- 5
- High 2 Medium 3
- 2 high, 3 medium
- Released
- August 21, 2026
- Per Sonatype's release pages.
- End of life
- Sonatype status: General Availability. General availability ends August 5, 2027. Sunset on February 5, 2028.
- Behind latest
- 28 days behind 3.96.2 (released September 18, 2026).
Sonatype's policy: Sonatype Nexus Repository releases are considered generally available and fully supported for a term of 1 year after the version's release date. Sonatype provides extended maintenance for each Sonatype Nexus Repository version for an additional 6 months before that version is considered sunset.
Sources: NVD (exact CPE match and the published configurations), the CVE Program record (the vendor's CNA entry with its affected and fixed versions), Sonatype's security advisories, release notes and end-of-life page. Pulled September 18, 2026. Every CVE row links to its NVD record and to the vendor's advisory.
CVEs that affect 3.95.2 (5)
Two verdicts per row, side by side: what NVD's exact CPE match says, and what Sonatype's own CVE record says. A CVE counts when either source says affected. Open a row's sources for the raw ranges.
| CVE | Severity | Affected per NVD | Affected per Sonatype | Fix on your branch |
|---|---|---|---|---|
| CVE-2026-77124 published September 2, 2026 In affected versions of Nexus Repository 3, the script execution endpoint (POST /service/rest/v1/script/{name}/run) did not verify whether script execution had been administratively disabled. An account holding script-execution permission could continue to run previously-created scripts even after an administrator set nexus.scripts.allowCreation=false, undermining the expectation that this setting fully blocks script execution. | High7.5 CVSS 4.0 7.5, rated by Sonatype (CNA) | yes | yes | No fix on your branch; the nearest fix is 3.96.0. Latest: 3.96.2. |
Sources for CVE-2026-77124 and 3.95.2 Hide sources
| ||||
| CVE-2026-77125 published September 2, 2026 A vulnerability was identified in Sonatype Nexus Repository 3 in which two blobstore group management REST API endpoints did not correctly enforce the intended authorization check. A user granted only the nexus:blobstores:create permission could invoke these endpoints to convert an existing blobstore into a group blobstore, an action that should require the nexus:blobstores:update permission instead. This could result in unauthorized modification of blobstore configuration without administrator approval. The nexus:blobstores:create permission is a named permission that must be explicitly granted by an administrator; it is not held by default. | High7.1 CVSS 4.0 7.1, rated by Sonatype (CNA) | yes | yes | No fix on your branch; the nearest fix is 3.96.0. Latest: 3.96.2. |
Sources for CVE-2026-77125 and 3.95.2 Hide sources
| ||||
| CVE-2026-0600 published January 14, 2026 Server-Side Request Forgery (SSRF) vulnerability in Sonatype Nexus Repository 3 versions 3.0.0 and later allows authenticated administrators to configure proxy repositories with URLs that can access unintended network destinations, potentially including cloud metadata services and internal network resources. A workaround configuration is available starting in version 3.88.0, but the product remains vulnerable by default. | Medium6.2 CVSS 4.0 6.2, rated by Sonatype (CNA) | no NVD data | yes | No fixed version published. Sonatype names a workaround from Sonatype Nexus Repository 3.88.0 (CE/Pro). Latest: 3.96.2. |
Sources for CVE-2026-0600 and 3.95.2 Hide sources
| ||||
| CVE-2026-77123 published September 2, 2026 Nexus Repository 3 contains a sensitive information disclosure vulnerability in the capability read API. An account holding the nexus:capabilities:read privilege can retrieve the plaintext shared secret configured on a webhook capability, which is intended to be masked from all API responses. This issue affects Nexus Repository 3 versions 3.2.0 through 3.95.x, and is fixed in version 3.96.0. | Medium6.0 CVSS 4.0 6.0, rated by Sonatype (CNA) | yes | yes | No fix on your branch; the nearest fix is 3.96.0. Latest: 3.96.2. |
Sources for CVE-2026-77123 and 3.95.2 Hide sources
| ||||
| CVE-2026-77122 published September 2, 2026 An authorization flaw in the REST API repository details endpoint (GET /service/rest/v1/repositories/{repositoryName}) in Sonatype Nexus Repository 3 allowed an account holding read or browse permission on a group repository to retrieve metadata for member repositories on which it held no direct permission, by requesting the endpoint directly for the member repository name. For proxy repositories, the disclosed metadata includes the configured remote URL, which may reveal internal upstream hostnames. This includes the anonymous user if it has been granted this permission; whether the anonymous user holds this permission depends on the role and permission configuration of the specific installation. | Medium5.3 CVSS 4.0 5.3, rated by Sonatype (CNA) | yes | yes | No fix on your branch; the nearest fix is 3.96.0. Latest: 3.96.2. |
Sources for CVE-2026-77122 and 3.95.2 Hide sources
| ||||
61 other Sonatype Nexus Repository CVEs on record that do not affect 3.95.2
Each of these is fixed at or before 3.95.2 on its branch, or its published range does not include this version. The fix column shows the fix this version already carries.
| CVE | Severity | Affected per NVD | Affected per Sonatype | Fix on your branch |
|---|---|---|---|---|
| CVE-2019-7238 published March 21, 2019 | Critical9.8 CVSS 3.1 9.8, rated by NVD | no | no Sonatype CNA range | No Sonatype CNA range for this CVE (assigned by MITRE); NVD's published range does not include this version. |
Sources for CVE-2019-7238 and 3.95.2 Hide sources
| ||||
| CVE-2019-9629 published July 8, 2019 | Critical9.8 CVSS 3.0 9.8, rated by NVD | no | no Sonatype CNA range | No Sonatype CNA range for this CVE (assigned by MITRE); NVD's published range does not include this version. |
Sources for CVE-2019-9629 and 3.95.2 Hide sources
| ||||
| CVE-2026-5189 published April 15, 2026 | Critical9.8 CVSS 3.1 9.8, rated by NVD | no | no | This version is outside the affected range. |
Sources for CVE-2026-5189 and 3.95.2 Hide sources
| ||||
| CVE-2026-17601 published August 7, 2026 | High8.9 CVSS 4.0 8.9, rated by Sonatype (CNA) | no | no | Already fixed: this version is at or past 3.95.0. |
Sources for CVE-2026-17601 and 3.95.2 Hide sources
| ||||
| CVE-2020-10199 published April 1, 2020 | High8.8 CVSS 3.1 8.8, rated by NVD | no | no | This version is outside the affected range. |
Sources for CVE-2020-10199 and 3.95.2 Hide sources
| ||||
| CVE-2020-11444 published April 2, 2020 | High8.8 CVSS 3.1 8.8, rated by NVD | no | no | This version is outside the affected range. |
Sources for CVE-2020-11444 and 3.95.2 Hide sources
| ||||
| CVE-2020-11753 published April 20, 2020 | High8.8 CVSS 3.1 8.8, rated by NVD | no | no | This version is outside the affected range. |
Sources for CVE-2020-11753 and 3.95.2 Hide sources
| ||||
| CVE-2020-15871 published July 31, 2020 | High8.8 CVSS 3.1 8.8, rated by NVD | no | no Sonatype CNA range | No Sonatype CNA range for this CVE (assigned by MITRE); NVD's published range does not include this version. |
Sources for CVE-2020-15871 and 3.95.2 Hide sources
| ||||
| CVE-2026-3199 published April 8, 2026 | High8.8 CVSS 3.1 8.8, rated by NVD | no | no | This version is outside the affected range. |
Sources for CVE-2026-3199 and 3.95.2 Hide sources
| ||||
| CVE-2026-11403 published July 14, 2026 | High8.7 CVSS 4.0 8.7, rated by Sonatype (CNA) | no | no | This version is outside the affected range. |
Sources for CVE-2026-11403 and 3.95.2 Hide sources
| ||||
| CVE-2026-17600 published August 7, 2026 | High8.7 CVSS 4.0 8.7, rated by Sonatype (CNA) | no | no | Already fixed: this version is at or past 3.95.0. |
Sources for CVE-2026-17600 and 3.95.2 Hide sources
| ||||
| CVE-2026-17603 published August 7, 2026 | High8.7 CVSS 4.0 8.7, rated by Sonatype (CNA) | no | no | Already fixed: this version is at or past 3.95.0. |
Sources for CVE-2026-17603 and 3.95.2 Hide sources
| ||||
| CVE-2026-10748 published June 16, 2026 | High8.6 CVSS 4.0 8.6, rated by Sonatype (CNA) | no | no | This version is outside the affected range. |
Sources for CVE-2026-10748 and 3.95.2 Hide sources
| ||||
| CVE-2026-14644 published August 7, 2026 | High8.6 CVSS 4.0 8.6, rated by Sonatype (CNA) | no | no | Already fixed: this version is at or past 3.95.0. |
Sources for CVE-2026-14644 and 3.95.2 Hide sources
| ||||
| CVE-2021-40143 published September 7, 2021 | High8.2 CVSS 3.1 8.2, rated by NVD | no | no | This version is outside the affected range. |
Sources for CVE-2021-40143 and 3.95.2 Hide sources
| ||||
| CVE-2026-14504 published July 14, 2026 | High8.2 CVSS 4.0 8.2, rated by Sonatype (CNA) | no NVD data | no | This version is outside the affected range. |
Sources for CVE-2026-14504 and 3.95.2 Hide sources
| ||||
| CVE-2026-17594 published August 7, 2026 | High8.2 CVSS 4.0 8.2, rated by Sonatype (CNA) | no | no | Already fixed: this version is at or past 3.95.0. |
Sources for CVE-2026-17594 and 3.95.2 Hide sources
| ||||
| CVE-2018-16620 published November 15, 2018 | High7.5 CVSS 3.0 7.5, rated by NVD | no | no | This version is outside the affected range. |
Sources for CVE-2018-16620 and 3.95.2 Hide sources
| ||||
| CVE-2019-9630 published July 8, 2019 | High7.5 CVSS 3.0 7.5, rated by NVD | no | no Sonatype CNA range | No Sonatype CNA range for this CVE (assigned by MITRE); NVD's published range does not include this version. |
Sources for CVE-2019-9630 and 3.95.2 Hide sources
| ||||
| CVE-2020-15868 published August 12, 2020 | High7.5 CVSS 3.1 7.5, rated by NVD | no | no Sonatype CNA range | No Sonatype CNA range for this CVE (assigned by MITRE); NVD's published range does not include this version. |
Sources for CVE-2020-15868 and 3.95.2 Hide sources
| ||||
| CVE-2024-4956 published May 16, 2024 | High7.5 CVSS 3.1 7.5, rated by Sonatype (CNA) | no NVD data | no | This version is outside the affected range. |
Sources for CVE-2024-4956 and 3.95.2 Hide sources
| ||||
| CVE-2026-3329 published June 11, 2026 | High7.5 CVSS 3.1 7.5, rated by NVD | no | no | This version is outside the affected range. |
Sources for CVE-2026-3329 and 3.95.2 Hide sources
| ||||
| CVE-2018-16621 published November 15, 2018 | High7.2 CVSS 3.1 7.2, rated by NVD | no | no | This version is outside the affected range. |
Sources for CVE-2018-16621 and 3.95.2 Hide sources
| ||||
| CVE-2019-16530 published October 21, 2019 | High7.2 CVSS 3.1 7.2, rated by NVD | no | no | This version is outside the affected range. |
Sources for CVE-2019-16530 and 3.95.2 Hide sources
| ||||
| CVE-2020-10204 published April 1, 2020 | High7.2 CVSS 3.1 7.2, rated by NVD | no | no Sonatype CNA range | No Sonatype CNA range for this CVE (assigned by MITRE); NVD's published range does not include this version. |
Sources for CVE-2020-10204 and 3.95.2 Hide sources
| ||||
| CVE-2026-17593 published August 7, 2026 | High7.2 CVSS 4.0 7.2, rated by Sonatype (CNA) | no | no | Already fixed: this version is at or past 3.95.0. |
Sources for CVE-2026-17593 and 3.95.2 Hide sources
| ||||
| CVE-2026-17599 published August 7, 2026 | Medium6.9 CVSS 4.0 6.9, rated by Sonatype (CNA) | no | no | Already fixed: this version is at or past 3.95.0. |
Sources for CVE-2026-17599 and 3.95.2 Hide sources
| ||||
| CVE-2020-29436 published December 17, 2020 | Medium6.5 CVSS 3.1 6.5, rated by NVD | no | no Sonatype CNA range | No Sonatype CNA range for this CVE (assigned by MITRE); NVD's published range does not include this version. |
Sources for CVE-2020-29436 and 3.95.2 Hide sources
| ||||
| CVE-2024-5764 published October 23, 2024 | Medium6.5 CVSS 3.1 6.5, rated by NVD | no | no | This version is outside the affected range. |
Sources for CVE-2024-5764 and 3.95.2 Hide sources
| ||||
| CVE-2026-17596 published August 7, 2026 | Medium6.3 CVSS 4.0 6.3, rated by Sonatype (CNA) | no | no | Already fixed: this version is at or past 3.95.0. |
Sources for CVE-2026-17596 and 3.95.2 Hide sources
| ||||
| CVE-2018-16619 published November 15, 2018 | Medium6.1 CVSS 3.0 6.1, rated by NVD | no | no | This version is outside the affected range. |
Sources for CVE-2018-16619 and 3.95.2 Hide sources
| ||||
| CVE-2018-5306 published February 9, 2018 | Medium6.1 CVSS 3.0 6.1, rated by NVD | no | no | This version is outside the affected range. |
Sources for CVE-2018-5306 and 3.95.2 Hide sources
| ||||
| CVE-2020-15870 published July 31, 2020 | Medium6.1 CVSS 3.1 6.1, rated by NVD | no | no | This version is outside the affected range. |
Sources for CVE-2020-15870 and 3.95.2 Hide sources
| ||||
| CVE-2021-29159 published April 28, 2021 | Medium6.1 CVSS 3.1 6.1, rated by NVD | no | no | This version is outside the affected range. |
Sources for CVE-2021-29159 and 3.95.2 Hide sources
| ||||
| CVE-2026-3438 published April 8, 2026 | Medium6.1 CVSS 3.1 6.1, rated by NVD | no | no | This version is outside the affected range. |
Sources for CVE-2026-3438 and 3.95.2 Hide sources
| ||||
| CVE-2019-14469 published August 22, 2019 | Medium5.4 CVSS 3.0 5.4, rated by NVD | no | no | This version is outside the affected range. |
Sources for CVE-2019-14469 and 3.95.2 Hide sources
| ||||
| CVE-2020-15869 published July 31, 2020 | Medium5.4 CVSS 3.1 5.4, rated by NVD | no | no | This version is outside the affected range. |
Sources for CVE-2020-15869 and 3.95.2 Hide sources
| ||||
| CVE-2021-37152 published August 10, 2021 | Medium5.4 CVSS 3.1 5.4, rated by NVD | no | no | This version is outside the affected range. |
Sources for CVE-2021-37152 and 3.95.2 Hide sources
| ||||
| CVE-2021-30635 published April 27, 2021 | Medium5.3 CVSS 3.1 5.3, rated by NVD | no | no | This version is outside the affected range. |
Sources for CVE-2021-30635 and 3.95.2 Hide sources
| ||||
| CVE-2026-17595 published August 7, 2026 | Medium5.3 CVSS 4.0 5.3, rated by Sonatype (CNA) | no | no | Already fixed: this version is at or past 3.95.0. |
Sources for CVE-2026-17595 and 3.95.2 Hide sources
| ||||
| CVE-2026-17598 published August 7, 2026 | Medium5.3 CVSS 4.0 5.3, rated by Sonatype (CNA) | no | no | Already fixed: this version is at or past 3.95.0. |
Sources for CVE-2026-17598 and 3.95.2 Hide sources
| ||||
| CVE-2026-7494 published July 14, 2026 | Medium5.3 CVSS 4.0 5.3, rated by Sonatype (CNA) | no NVD data | no | This version is outside the affected range. |
Sources for CVE-2026-7494 and 3.95.2 Hide sources
| ||||
| CVE-2026-77121 published September 2, 2026 | Medium5.3 CVSS 4.0 5.3, rated by Sonatype (CNA) | no | no | Already fixed: this version is at or past 3.95.0. |
Sources for CVE-2026-77121 and 3.95.2 Hide sources
| ||||
| CVE-2025-13488 published December 4, 2025 | Medium5.1 CVSS 4.0 5.1, rated by Sonatype (CNA) | no NVD data | no | This version is outside the affected range. |
Sources for CVE-2025-13488 and 3.95.2 Hide sources
| ||||
| CVE-2026-0601 published January 14, 2026 | Medium5.1 CVSS 4.0 5.1, rated by Sonatype (CNA) | no NVD data | no | This version is outside the affected range. |
Sources for CVE-2026-0601 and 3.95.2 Hide sources
| ||||
| CVE-2026-14645 published July 14, 2026 | Medium5.1 CVSS 4.0 5.1, rated by Sonatype (CNA) | no NVD data | no | This version is outside the affected range. |
Sources for CVE-2026-14645 and 3.95.2 Hide sources
| ||||
| CVE-2026-17597 published August 7, 2026 | Medium5.1 CVSS 4.0 5.1, rated by Sonatype (CNA) | no | no | Already fixed: this version is at or past 3.95.0. |
Sources for CVE-2026-17597 and 3.95.2 Hide sources
| ||||
| CVE-2026-3048 published May 11, 2026 | Medium5.1 CVSS 4.0 5.1, rated by Sonatype (CNA) | no | no | This version is outside the affected range. |
Sources for CVE-2026-3048 and 3.95.2 Hide sources
| ||||
| CVE-2026-7308 published May 11, 2026 | Medium5.1 CVSS 4.0 5.1, rated by Sonatype (CNA) | no NVD data | no | This version is outside the affected range. |
Sources for CVE-2026-7308 and 3.95.2 Hide sources
| ||||
| CVE-2020-11415 published April 27, 2020 | Medium4.9 CVSS 3.1 4.9, rated by NVD | no | no Sonatype CNA range | No Sonatype CNA range for this CVE (assigned by MITRE); NVD's published range does not include this version. |
Sources for CVE-2020-11415 and 3.95.2 Hide sources
| ||||
| CVE-2020-24622 published August 25, 2020 | Medium4.9 CVSS 3.1 4.9, rated by NVD | no | no | This version is outside the affected range. |
Sources for CVE-2020-24622 and 3.95.2 Hide sources
| ||||
| CVE-2021-29158 published April 23, 2021 | Medium4.9 CVSS 3.1 4.9, rated by NVD | no | no | This version is outside the affected range. |
Sources for CVE-2021-29158 and 3.95.2 Hide sources
| ||||
| CVE-2026-10741 published June 17, 2026 | Medium4.9 CVSS 3.1 4.9, rated by NVD | no | no | This version is outside the affected range. |
Sources for CVE-2026-10741 and 3.95.2 Hide sources
| ||||
| CVE-2026-14646 published July 14, 2026 | Medium4.9 CVSS 4.0 4.9, rated by Sonatype (CNA) | no | no | This version is outside the affected range. |
Sources for CVE-2026-14646 and 3.95.2 Hide sources
| ||||
| CVE-2018-12100 published June 11, 2018 | Medium4.8 CVSS 3.0 4.8, rated by NVD | no | no | This version is outside the affected range. |
Sources for CVE-2018-12100 and 3.95.2 Hide sources
| ||||
| CVE-2020-10203 published April 1, 2020 | Medium4.8 CVSS 3.1 4.8, rated by NVD | no | no Sonatype CNA range | No Sonatype CNA range for this CVE (assigned by MITRE); NVD's published range does not include this version. |
Sources for CVE-2020-10203 and 3.95.2 Hide sources
| ||||
| CVE-2021-34553 published June 18, 2021 | Medium4.3 CVSS 3.1 4.3, rated by NVD | no | no | This version is outside the affected range. |
Sources for CVE-2021-34553 and 3.95.2 Hide sources
| ||||
| CVE-2021-42568 published November 2, 2021 | Medium4.3 CVSS 3.1 4.3, rated by NVD | no | no Sonatype CNA range | No Sonatype CNA range for this CVE (assigned by MITRE); NVD's published range does not include this version. |
Sources for CVE-2021-42568 and 3.95.2 Hide sources
| ||||
| CVE-2021-43293 published November 4, 2021 | Medium4.3 CVSS 3.1 4.3, rated by NVD | no | no Sonatype CNA range | No Sonatype CNA range for this CVE (assigned by MITRE); NVD's published range does not include this version. |
Sources for CVE-2021-43293 and 3.95.2 Hide sources
| ||||
| CVE-2021-43961 published March 17, 2022 | Medium4.3 CVSS 3.1 4.3, rated by NVD | no | no | This version is outside the affected range. |
Sources for CVE-2021-43961 and 3.95.2 Hide sources
| ||||
| CVE-2022-27907 published March 30, 2022 | Medium4.3 CVSS 3.1 4.3, rated by NVD | no | no | This version is outside the affected range. |
Sources for CVE-2022-27907 and 3.95.2 Hide sources
| ||||
About this page and CloudRepo
CloudRepo is a managed artifact repository, so there is no Artifactory or Nexus server for you to patch. In over 10 years of operation, CloudRepo has experienced no known security breaches. This page is not a scan of your server: the data is NVD's and the vendor's, linked on every row, pulled on September 18, 2026.
Read next
Look up another version