CVE-2026-17597: Nexus Repository 3 - Server-Side Request Forgery via Email Configuration Verification
Nexus Repository 3 contains a Server-Side Request Forgery (SSRF) vulnerability in the email configuration verification feature. A user holding the nexus:settings:update permission could submit arbitrary host and port values to the email test/verification endpoint, causing the server to attempt outbound network connections to internal or otherwise restricted network addresses. Differences in the server's response could be used to infer whether internal hosts and ports are reachable. This issue affects Nexus Repository 3 CE/Pro versions up to and including 3.94.1, and is fixed in version 3.95.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Nexus Repository 3to a version that resolves this vulnerability.Fixed in 3.95.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-17597?
CVE-2026-17597 has a risk rating of 37.
How do I fix CVE-2026-17597?
To fix CVE-2026-17597, ensure you upgrade to the patched version of Sonatype Nexus Repository 3 that addresses this vulnerability.
What is the impact of CVE-2026-17597?
CVE-2026-17597 allows an attacker to exploit Server-Side Request Forgery via the email configuration verification feature.
Who is affected by CVE-2026-17597?
Any user with the nexus:settings:update permission in Sonatype Nexus Repository 3 is at risk of CVE-2026-17597.
What type of vulnerability is CVE-2026-17597?
CVE-2026-17597 is classified as a Server-Side Request Forgery (SSRF) vulnerability.