# CVE-2026-7494

Nexus Repository 3 is vulnerable to Server-Side Request Forgery (SSRF) via the SSL Certificate Retrieval endpoint. A user holding the nexus:ssl-truststore:read permission could cause the server to initiate outbound connections to internal or otherwise restricted network hosts. This issue affects Nexus Repository 3.0.0 through versions prior to 3.94.0.

Published Jul 3, 2026  
[support.sonatype.com](https://support.sonatype.com/hc/en-us/articles/53126069518227)

## CVSS Score
Medium  
5.3

## Security Details
### Components Impacted
- Sonatype Research

### CVE Description
Nexus Repository 3 is vulnerable to Server-Side Request Forgery (SSRF) via the SSL Certificate Retrieval endpoint. A user holding the nexus:ssl-truststore:read permission could cause the server to initiate outbound connections to internal or otherwise restricted network hosts. This issue affects Nexus Repository 3.0.0 through versions prior to 3.94.0.

Published Jul 3, 2026

### CVSS Score & Severity
5.3 Medium

### CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:L/SI:N/SA:N

### EPSS Score
0.146%

### Malware
malware

### KEV Status
Not in KEV Catalog: No known exploits

### Vulnerable Methods
- com/sonatype/nexus/ssl/plugin/internal/CertificateRetriever.retrieveCertificates(Ljava/lang/String;Ljava/lang/Integer;Ljava/lang/String;)
  - JVM Vulnerable params: 0, 1
- com/sonatype/nexus/ssl/plugin/internal/CertificateRetriever.retrieveCertificatesFromHttpsServer(Ljava/lang/String;I)
  - JVM Vulnerable params: 0, 1
- org/sonatype/nexus/ssl/CertificateRetriever.retrieveCertificates(Ljava/lang/String;Ljava/lang/Integer;Ljava/lang/String;)
  - JVM Vulnerable params: 0, 1
- org/sonatype/nexus/ssl/CertificateRetriever.retrieveCertificatesFromHttpsServer(Ljava/lang/String;I)
  - JVM Vulnerable params: 0, 1

### Affected Ecosystems
affected

### Source
National Vulnerability Database

### References
- [support.sonatype.com](https://support.sonatype.com/hc/en-us/articles/53126069518227)
