CVE-2026-7494: Nexus Repository - SSRF in SSL Certificate Retrieval
Nexus Repository 3 is vulnerable to Server-Side Request Forgery (SSRF) via the SSL Certificate Retrieval endpoint. A user holding the nexus:ssl-truststore:read permission could cause the server to initiate outbound connections to internal or otherwise restricted network hosts. This issue affects Nexus Repository 3.0.0 through versions prior to 3.94.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
nexus-repositoryto a version that resolves this vulnerability.Fixed in 3.94.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7494?
The severity of CVE-2026-7494 is rated as medium with a CVSS score of 5.3.
What does CVE-2026-7494 affect?
CVE-2026-7494 affects Sonatype Nexus Repository 3 and involves a Server-Side Request Forgery vulnerability.
How do I fix CVE-2026-7494?
To fix CVE-2026-7494, you should upgrade to the latest patched version of Sonatype Nexus Repository 3.
What are the potential risks of CVE-2026-7494?
The potential risks of CVE-2026-7494 include unauthorized outbound connections to internal or restricted network hosts.
Who is affected by CVE-2026-7494?
Users holding the nexus:ssl-truststore:read permission in Sonatype Nexus Repository 3 are affected by CVE-2026-7494.