Threats Tagged 'cve-2026-17595'
View all threats tagged with 'cve-2026-17595'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-17595'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-17595: CWE-497 Exposure of Sensitive System Information to an Unauthorized Control Sphere in Sonatype Nexus Repository 3CVE-2026-17595 0 Nexus Repository 3 did not fully sandbox JEXL expressions used in Content Selectors. An account holding the nexus:selectors:create permission could construct an expression that read Java object properties not intended to be exposed to the expression engine, disclosing internal JVM class metadata such as class and classloader names. This issue does not permit method invocation, object construction, or arbitrary code execution. This has been fixed by restricting property access in the JEXL sandbox to the intended data types. Join the discussion | CVE Database V5 | 08/07/2026, 16:07:43 UTC Added: 08/07/2026, 16:26:45 UTC |
Showing 1 to 1 of 1 result