Sonatype Nexus Repository 3 Server-Side Request Forgery Vulnerability

Vulnerability

A Server-Side Request Forgery (SSRF) vulnerability exists in Sonatype Nexus Repository 3, affecting versions 3.0.0 and later. This vulnerability allows authenticated administrators to configure proxy repositories with URLs that can access unintended network destinations, such as cloud metadata services and internal network resources. While a workaround is available starting in version 3.88.0, the product remains vulnerable by default.

Impact

Exploitation of this vulnerability could lead to unauthorized access to internal network resources or cloud metadata services, potentially allowing for credential theft or access to sensitive internal services.

Remediation

Users should upgrade to Sonatype Nexus Repository 3.88.0 or later, enable private network validation, and review existing proxy repository configurations. For environments unable to upgrade immediately, temporary mitigations include auditing proxy repository configurations, restricting administrator access, implementing network-level egress filtering, and monitoring proxy repository configuration changes through audit logs.

Added: Jan 14, 2026, 11:27 PM
Updated: Jan 14, 2026, 11:27 PM

Vulnerability Rating

Custom Algorithm
spread
6.2
impact
0.8
exploitability
3.5
remediation
7.9
relevance
2.0
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.