Nexus Repository 3 - Server-Side Request Forgery in Proxy Repository Configuration
Published Jan 14, 2026
6.2
MEDIUMCVSS 4.0
EPSS 0.30%
Description
Server-Side Request Forgery (SSRF) vulnerability in Sonatype Nexus Repository 3 versions 3.0.0 and later allows authenticated administrators to configure proxy repositories with URLs that can access unintended network destinations, potentially including cloud metadata services and internal network resources. A workaround configuration is available starting in version 3.88.0, but the product remains vulnerable by default.
Affected products
-
Affected
- 3.0.0
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Sonatype | Nexus Repository | unaffected | Affected
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Starting in version 3.88.0, administrators can configure the private network validation setting to block proxy repositories from accessing private network destinations. Cloud metadata endpoints (169.254.169.254) are always blocked regardless of configuration. See the security documentation at https://help.sonatype.com/en/securing-nexus-repository-manager.html for detailed configuration steps.
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-2838 Advisory
- https://support.sonatype.com/hc/en-us/articles/47928855816595 vendor-advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-2838 | Advisory | |
| https://support.sonatype.com/hc/en-us/articles/47928855816595 | vendor-advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data