CVE-2026-14646
As of 2026-07-15, CVE-2026-14646 is a CVSS 4.9 vulnerability. EPSS exploitation probability 0.3%. Threadlinqs Intelligence tracks 1 threat exploiting it.
Last updated: 2026-07-15
Nexus Repository 3 did not apply its existing Server-Side Request Forgery (SSRF) protections to HTTP redirect targets returned by proxy repository upstream servers. Any user with read access to a proxy repository backed by an attacker-controlled or compromised upstream server — including an anonymous user, if anonymous access is enabled — could receive a response from an internal network address or cloud metadata endpoint as repository content, potentially exposing sensitive information such as cloud IAM credentials.
Weaknesses (CWE)
CWE-918
Threats tracking this CVE
References
- https://help.sonatype.com/en/sonatype-nexus-repository-3-94-0-release-notes.html
- https://support.sonatype.com/hc/en-us/articles/53165019641363/
← all vulnerabilities · Markdown version · Threadlinqs Intelligence
Enriched from CVE.org, NVD (this product uses the NVD API but is not endorsed or certified by the NVD), FIRST EPSS, CISA KEV, and GitHub Security Advisories.