PT-2026-69059 · Sonatype · Nexus Repository

CVE-2026-17597

·

Published

2026-08-07

·

Updated

2026-08-07

CVSS v4.0

5.1

Medium

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Nexus Repository 3 versions prior to 3.95.0
Description A Server-Side Request Forgery (SSRF) issue exists in the email configuration verification feature. A user with the nexus:settings:update permission can submit arbitrary host and port values to the email test/verification endpoint, forcing the server to initiate outbound network connections to internal or restricted network addresses. By analyzing differences in the server responses, an attacker can determine if specific internal hosts and ports are reachable.
Recommendations Update to version 3.95.0.

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-17597

Affected Products

Nexus Repository