CVE-2026-7494 | Security Details | Sonatype Guide
CVE-2026-7494
Nexus Repository 3 is vulnerable to Server-Side Request Forgery (SSRF) via the SSL Certificate Retrieval endpoint. A user holding the nexus:ssl-truststore:read permission could cause the server to initiate outbound connections to internal or otherwise restricted network hosts. This issue affects Nexus Repository 3.0.0 through versions prior to 3.94.0.
Published Jul 3, 2026
support.sonatype.com
CVSS Score
Medium
5.3
Security Details
Components Impacted
- Sonatype Research
CVE Description
Nexus Repository 3 is vulnerable to Server-Side Request Forgery (SSRF) via the SSL Certificate Retrieval endpoint. A user holding the nexus:ssl-truststore:read permission could cause the server to initiate outbound connections to internal or otherwise restricted network hosts. This issue affects Nexus Repository 3.0.0 through versions prior to 3.94.0.
Published Jul 3, 2026
CVSS Score & Severity
5.3 Medium
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:L/SI:N/SA:N
EPSS Score
0.146%
Malware
malware
KEV Status
Not in KEV Catalog: No known exploits
Vulnerable Methods
- com/sonatype/nexus/ssl/plugin/internal/CertificateRetriever.retrieveCertificates(Ljava/lang/String;Ljava/lang/Integer;Ljava/lang/String;)
- JVM Vulnerable params: 0, 1
- com/sonatype/nexus/ssl/plugin/internal/CertificateRetriever.retrieveCertificatesFromHttpsServer(Ljava/lang/String;I)
- JVM Vulnerable params: 0, 1
- org/sonatype/nexus/ssl/CertificateRetriever.retrieveCertificates(Ljava/lang/String;Ljava/lang/Integer;Ljava/lang/String;)
- JVM Vulnerable params: 0, 1
- org/sonatype/nexus/ssl/CertificateRetriever.retrieveCertificatesFromHttpsServer(Ljava/lang/String;I)
- JVM Vulnerable params: 0, 1
Affected Ecosystems
affected
Source
National Vulnerability Database