CVE-2026-0600 | Security Details | Sonatype Guide

CVE-2026-0600

Server-Side Request Forgery (SSRF) vulnerability in Sonatype Nexus Repository 3 versions 3.0.0 and later allows authenticated administrators to configure proxy repositories with URLs that can access unintended network destinations, potentially including cloud metadata services and internal network resources. A workaround configuration is available starting in version 3.88.0, but the product remains vulnerable by default.

Published Jan 6, 2026

CVSS Score

Medium

6.2

Security Details

Components Impacted

CVE Description

CVE-2026-0600

CWE

CWE-918 Learn more about CWE-918

CVE Description: Server-Side Request Forgery (SSRF) vulnerability in Sonatype Nexus Repository 3 versions 3.0.0 and later allows authenticated administrators to configure proxy repositories with URLs that can access unintended network destinations, potentially including cloud metadata services and internal network resources. A workaround configuration is available starting in version 3.88.0, but the product remains vulnerable by default.

Published: Jan 6, 2026

CVSS Score & Severity

6.2 Medium

CVSS Vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:L/SA:N

EPSS Score

0.063%

Malware

malware

KEV Status

Not in KEV Catalog: No known exploits

Vulnerable Methods

JVM Vulnerable params: 2, 0, 0

Affected Ecosystems

Source: National Vulnerability Database

References