Known Vulnerabilities for products from Sonatype
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Sonatype".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-77125 json | A vulnerability was identified in Sonatype Nexus Repository 3 in which two blobstore group management REST API endpoints did ... | Not Provided | 2026-09-02 | 2026-09-22 |
| CVE-2026-77124 json | In affected versions of Nexus Repository 3, the script execution endpoint (POST /service/rest/v1/script/{name}/run) did not v... | Not Provided | 2026-09-02 | 2026-09-22 |
| CVE-2026-77123 json | Nexus Repository 3 contains a sensitive information disclosure vulnerability in the capability read API. An account holding t... | Not Provided | 2026-09-02 | 2026-09-22 |
| CVE-2026-77122 json | An authorization flaw in the REST API repository details endpoint (GET /service/rest/v1/repositories/{repositoryName}) in Son... | Not Provided | 2026-09-02 | 2026-09-22 |
| CVE-2026-77121 json | A user account with permission to deploy artifacts to a hosted Maven repository could upload a POM file containing an oversiz... | Not Provided | 2026-09-02 | 2026-10-07 |
| CVE-2026-17603 json | Nexus Repository 3 did not sufficiently restrict which HikariCP connection-pool properties could be set through the DataStore... | Not Provided | 2026-08-07 | 2026-09-22 |
| CVE-2026-17601 json | A user holding a permission to update privilege definitions could modify a wildcard privilege already assigned to their own r... | Not Provided | 2026-08-07 | 2026-09-23 |
| CVE-2026-17600 json | Not Provided | 2026-08-07 | 2026-08-07 | |
| CVE-2026-17599 json | Nexus Repository 3 contained an endpoint used to change the administrator account password during initial onboarding. This en... | Not Provided | 2026-08-07 | 2026-09-22 |
| CVE-2026-17598 json | Sonatype Nexus Repository 3 did not properly filter internal configuration keys from user-supplied task properties when creat... | Not Provided | 2026-08-07 | 2026-09-22 |
| CVE-2026-17597 json | Nexus Repository 3 contains a Server-Side Request Forgery (SSRF) vulnerability in the email configuration verification featur... | Not Provided | 2026-08-07 | 2026-09-22 |
| CVE-2026-17596 json | Nexus Repository 3 was found to be vulnerable to stored cross-site scripting (XSS). A user with the nexus:blobstores:create o... | Not Provided | 2026-08-07 | 2026-09-22 |
| CVE-2026-17595 json | Nexus Repository 3 did not fully sandbox JEXL expressions used in Content Selectors. An account holding the nexus:selectors:c... | Not Provided | 2026-08-07 | 2026-09-22 |
| CVE-2026-17594 json | Nexus Repository 3 CE/Pro versions 3.0.0 through 3.94.x contain an incorrect authorization vulnerability (CWE-863) in the rep... | Not Provided | 2026-08-07 | 2026-09-22 |
| CVE-2026-17593 json | An account holding the nexus:settings:update permission in Nexus Repository 3 (or the equivalent nexus:settings permission in... | Not Provided | 2026-08-07 | 2026-09-22 |
| CVE-2026-14646 json | Nexus Repository 3 did not apply its existing Server-Side Request Forgery (SSRF) protections to HTTP redirect targets returne... | Not Provided | 2026-07-14 | 2026-09-22 |
| CVE-2026-14645 json | Nexus Repository 3 does not validate the destination of the "Webhook: Global" capability's configured URL before making an ou... | Not Provided | 2026-07-14 | 2026-09-22 |
| CVE-2026-14644 json | Nexus Repository 3 contained a privilege escalation vulnerability in the REST privileges API. An authenticated user with perm... | Not Provided | 2026-08-07 | 2026-09-22 |
| CVE-2026-14504 json | An authorization bypass in Nexus Repository 3's component upload API allowed a user with only read/browse privileges on a Swi... | Not Provided | 2026-07-14 | 2026-09-22 |
| CVE-2026-11403 json | A vulnerability in Sonatype Nexus Repository Manager's format-specific API key generation may allow a remote attacker to gain... | Not Provided | 2026-07-14 | 2026-09-22 |
Known software with vulnerabilities from Sonatype
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Sonatype | Nexus | 2.0.4 |
| Application | Sonatype | Nexus Iq Server | 1.12 |
| Application | Sonatype | Nexus Repository Manager | 2.0 |
| Application | Sonatype | Nexus Repository Manager 2 | 2.0 |
| Application | Sonatype | Nexus Repository Manager 3 | 3.0.0 |