拥有向托管的 Maven 仓库部署构件权限的用户账户,可以上传包含超大元数据字段的 POM 文件。这会导致后续尝试列出或浏览该仓库中的组件时永久失败,直到管理员修复底层数据。仅受影响的仓库会受到影响;其他仓库以及服务器整体的健康状况保持正常。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Sonatype | Nexus Repository 3 | 3.26.0< 3.95.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Sonatype | Nexus Repository 3 | 3.26.0 ~ 3.95.0 |
cpe:2.3:a:sonatype:nexus_repository_manager:3.26.0:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-77124 | 7.5 HIGH | Nexus Repository 3 - Script Execution Disable Setting Not Enforced |
| CVE-2026-77125 | 7.1 HIGH | Nexus Repository 3 - Incorrect Authorization on Blobstore Group Endpoints |
| CVE-2026-77123 | 6.0 MEDIUM | Nexus Repository 3 - Webhook Secret Disclosure via Capability Read API |
| CVE-2026-77122 | 5.3 MEDIUM | Nexus Repository 3 - Incorrect Authorization Allows Disclosure of Member Repository Metada |
No comments yet