Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:maven/org.sonatype.nexus/nexus-repository

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

Sonatype Nexus Repository 3 contains a vulnerability where active user sessions are not immediately terminated or permissions revoked when the user's account is deleted, deactivated, or password changed. This allows users with existing sessions to continue accessing the repository with their previous permissions until the session expires. The issue could lead to unauthorized access to read, modify, or delete repository content after access should have been revoked.

Join the discussion

Nexus Repository 3 contains a vulnerability where the DataStore configuration API does not sufficiently restrict which HikariCP connection-pool properties can be set. A user with the nx-datastores-update permission can set the connectionInitSql property to execute arbitrary SQL on every new database connection. When using the default H2 database backend, this flaw can lead to remote code execution as the Nexus process user.

Join the discussion

An authenticated user with upload permission to a hosted repository can store content that causes arbitrary JavaScript to execute in the browser of any user who browses that repository directory via the HTML index page in Sonatype Nexus Repository versions 3.6.0 through versions before 3.92.0. This could allow the attacker to perform actions in the context of the victim's session.

Join the discussion

CVE-2026-5189 is a critical vulnerability in Sonatype Nexus Repository Manager versions 3.0.0 through 3.70.5 involving the use of hard-coded credentials. An unauthenticated attacker with network access can exploit this issue if the non-default configuration nexus.orient.binaryListenerEnabled=true is enabled. Successful exploitation allows unauthorized read/write access to the internal database and execution of arbitrary OS commands as the Nexus process user. The vulnerability has a CVSS 4.

Join the discussion

CVE-2026-3199 is a critical vulnerability in Sonatype Nexus Repository versions 3.22.1 through 3.90.2. It affects the task management component, allowing an authenticated attacker with task creation permissions to execute arbitrary code by bypassing the nexus.scripts.allowCreation security control. The vulnerability is related to deserialization of untrusted data (CWE-502). The CVSS 4.

Join the discussion

CVE-2026-3438 is a reflected cross-site scripting (XSS) vulnerability in Sonatype Nexus Repository versions 3.0.0 through 3.90.2. It allows unauthenticated remote attackers to execute arbitrary JavaScript in a victim's browser via a specially crafted URL. Exploitation requires user interaction. The vulnerability has a medium severity with a CVSS score of 5.1. No official patch or remediation guidance is currently provided by the vendor.

Join the discussion

Server-Side Request Forgery (SSRF) vulnerability in Sonatype Nexus Repository 3 versions 3.0.0 and later allows authenticated administrators to configure proxy repositories with URLs that can access unintended network destinations, potentially including cloud metadata services and internal network resources. A workaround configuration is available starting in version 3.88.0, but the product remains vulnerable by default.

Join the discussion

A reflected cross-site scripting vulnerability exists in Nexus Repository 3 that allows unauthenticated attackers to execute arbitrary JavaScript in a victim's browser through a specially crafted request requiring user interaction.

Join the discussion

Due to a regression introduced in version 3.83.0, a security header is no longer applied to certain user-uploaded content served from repositories. This may allow an authenticated attacker with repository upload privileges to exploit a stored cross-site scripting (XSS) vulnerability with user context.

Join the discussion

Showing 1 to 9 of 9 results

Filters:Package: pkg:maven/org.sonatype.nexus/nexus-repository
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses