CVE-2026-3438: Nexus Repository 3 - Reflected Cross-Site Scripting (XSS) in ?describe Pages
A reflected cross-site scripting vulnerability exists in Sonatype Nexus Repository versions 3.0.0 through 3.90.2 that allows unauthenticated remote attackers to execute arbitrary JavaScript in a victim's browser through a specially crafted URL. Exploitation requires user interaction.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3438?
CVE-2026-3438 is classified as a reflected cross-site scripting (XSS) vulnerability, which poses a significant security risk.
How do I fix CVE-2026-3438?
To fix CVE-2026-3438, update Sonatype Nexus Repository to version 3.91.0 or later.
What types of attacks can CVE-2026-3438 enable?
CVE-2026-3438 can enable unauthenticated remote attackers to execute arbitrary JavaScript in a victim's browser.
Which versions of Sonatype Nexus Repository are affected by CVE-2026-3438?
CVE-2026-3438 affects Sonatype Nexus Repository versions from 3.0.0 through 3.90.2.
Is CVE-2026-3438 easy to exploit?
Yes, CVE-2026-3438 can be easily exploited by attackers due to its reliance on reflected input.