Known Vulnerabilities for products from Sonatype

Listed below are 20 of the newest known vulnerabilities associated with the vendor "Sonatype".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2026-77125 json A vulnerability was identified in Sonatype Nexus Repository 3 in which two blobstore group management REST API endpoints did ... Not Provided 2026-09-02 2026-09-22
CVE-2026-77124 json In affected versions of Nexus Repository 3, the script execution endpoint (POST /service/rest/v1/script/{name}/run) did not v... Not Provided 2026-09-02 2026-09-22
CVE-2026-77123 json Nexus Repository 3 contains a sensitive information disclosure vulnerability in the capability read API. An account holding t... Not Provided 2026-09-02 2026-09-22
CVE-2026-77122 json An authorization flaw in the REST API repository details endpoint (GET /service/rest/v1/repositories/{repositoryName}) in Son... Not Provided 2026-09-02 2026-09-22
CVE-2026-77121 json A user account with permission to deploy artifacts to a hosted Maven repository could upload a POM file containing an oversiz... Not Provided 2026-09-02 2026-10-07
CVE-2026-17603 json Nexus Repository 3 did not sufficiently restrict which HikariCP connection-pool properties could be set through the DataStore... Not Provided 2026-08-07 2026-09-22
CVE-2026-17601 json A user holding a permission to update privilege definitions could modify a wildcard privilege already assigned to their own r... Not Provided 2026-08-07 2026-09-23
CVE-2026-17600 json Not Provided 2026-08-07 2026-08-07
CVE-2026-17599 json Nexus Repository 3 contained an endpoint used to change the administrator account password during initial onboarding. This en... Not Provided 2026-08-07 2026-09-22
CVE-2026-17598 json Sonatype Nexus Repository 3 did not properly filter internal configuration keys from user-supplied task properties when creat... Not Provided 2026-08-07 2026-09-22
CVE-2026-17597 json Nexus Repository 3 contains a Server-Side Request Forgery (SSRF) vulnerability in the email configuration verification featur... Not Provided 2026-08-07 2026-09-22
CVE-2026-17596 json Nexus Repository 3 was found to be vulnerable to stored cross-site scripting (XSS). A user with the nexus:blobstores:create o... Not Provided 2026-08-07 2026-09-22
CVE-2026-17595 json Nexus Repository 3 did not fully sandbox JEXL expressions used in Content Selectors. An account holding the nexus:selectors:c... Not Provided 2026-08-07 2026-09-22
CVE-2026-17594 json Nexus Repository 3 CE/Pro versions 3.0.0 through 3.94.x contain an incorrect authorization vulnerability (CWE-863) in the rep... Not Provided 2026-08-07 2026-09-22
CVE-2026-17593 json An account holding the nexus:settings:update permission in Nexus Repository 3 (or the equivalent nexus:settings permission in... Not Provided 2026-08-07 2026-09-22
CVE-2026-14646 json Nexus Repository 3 did not apply its existing Server-Side Request Forgery (SSRF) protections to HTTP redirect targets returne... Not Provided 2026-07-14 2026-09-22
CVE-2026-14645 json Nexus Repository 3 does not validate the destination of the "Webhook: Global" capability's configured URL before making an ou... Not Provided 2026-07-14 2026-09-22
CVE-2026-14644 json Nexus Repository 3 contained a privilege escalation vulnerability in the REST privileges API. An authenticated user with perm... Not Provided 2026-08-07 2026-09-22
CVE-2026-14504 json An authorization bypass in Nexus Repository 3's component upload API allowed a user with only read/browse privileges on a Swi... Not Provided 2026-07-14 2026-09-22
CVE-2026-11403 json A vulnerability in Sonatype Nexus Repository Manager's format-specific API key generation may allow a remote attacker to gain... Not Provided 2026-07-14 2026-09-22

Known software with vulnerabilities from Sonatype

Type Vendor Product Version
ApplicationSonatypeNexus2.0.4
ApplicationSonatypeNexus Iq Server1.12
ApplicationSonatypeNexus Repository Manager2.0
ApplicationSonatypeNexus Repository Manager 22.0
ApplicationSonatypeNexus Repository Manager 33.0.0

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report