PT-2026-69059 · Sonatype · Nexus Repository
CVE-2026-17597
·
Published
2026-08-07
·
Updated
2026-08-07
CVSS v4.0
5.1
Medium
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Nexus Repository 3 versions prior to 3.95.0
Description
A Server-Side Request Forgery (SSRF) issue exists in the email configuration verification feature. A user with the
nexus:settings:update permission can submit arbitrary host and port values to the email test/verification endpoint, forcing the server to initiate outbound network connections to internal or restricted network addresses. By analyzing differences in the server responses, an attacker can determine if specific internal hosts and ports are reachable.Recommendations
Update to version 3.95.0.
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nexus Repository