
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-14646 is a Server-Side Request Forgery (SSRF) vulnerability in Sonatype Nexus Repository 3 that allows SSRF protections to be bypassed via HTTP redirect targets returned by proxy repository upstream servers. It affects all Nexus Repository 3 CE/Pro versions from 3.0.0 through 3.93.x, and was disclosed on July 14, 2026. The vulnerability was assigned a CVSS v4.0 base score of 4.9 (Medium) by Sonatype (Sonatype Advisory, Sonatype Release Notes).
The root cause is classified as CWE-918 (Server-Side Request Forgery), specifically that Nexus Repository 3 failed to apply its existing SSRF protections to HTTP redirect targets returned by proxy repository upstream servers. When a proxy repository's upstream server returns an HTTP redirect, Nexus follows the redirect without validating the destination against its SSRF blocklist, allowing the redirect to point to internal network addresses or cloud metadata endpoints (e.g., http://169.254.169.254/). Exploitation requires that the attacker control or compromise the upstream server configured for a proxy repository, and that the requesting user (including anonymous users if anonymous access is enabled) has read access to that proxy repository (Sonatype Advisory).
Successful exploitation allows an attacker to cause Nexus Repository to fetch and return content from internal network addresses or cloud metadata endpoints as repository content to the requesting user. The most significant risk is exposure of sensitive information such as cloud IAM credentials (e.g., AWS instance metadata at 169.254.169.254), which could enable lateral movement within cloud environments or privilege escalation. Confidentiality and availability of the Nexus instance itself are not directly impacted, but the integrity of the broader cloud environment may be compromised through credential theft (Sonatype Advisory).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported as of the disclosure date. CISA's SSVC assessment classifies exploitation as "none" and the vulnerability as not automatable, with only partial technical impact (Feedly). The EPSS score is approximately 0.265%, indicating a low probability of exploitation in the near term. The vulnerability was discovered and responsibly disclosed by researcher e0x1337 (elite) via Sonatype's Bug Bounty Program, and it is not listed in the CISA KEV catalog (Sonatype Advisory).
http://169.254.169.254/latest/meta-data/iam/security-credentials/.169.254.169.254, fd00:ec2::254) or unexpected internal network ranges, particularly following requests to proxy repositories.AccessKeyId, SecretAccessKey, Token) rather than legitimate package artifacts.Sonatype has released a fix in Nexus Repository 3 CE/Pro version 3.94.0 (released July 9, 2026); upgrading to this version or later is the recommended remediation (Sonatype Release Notes). As an immediate mitigation prior to upgrading, restrict proxy repository upstream configurations to trusted, known hosts and avoid enabling anonymous or broad read access on proxy repositories pointed at third-party or partner-controlled servers. If the Nexus instance runs in a cloud environment (AWS, GCP, Azure) and may have been exposed, Sonatype recommends rotating any instance/IAM credentials accessible via the cloud metadata service as a precaution (Sonatype Advisory).
Sonatype disclosed this vulnerability as part of a coordinated release of multiple Nexus Repository 3 security advisories on July 14, 2026, following responsible disclosure through their Bug Bounty Program. The vulnerability was credited to researcher e0x1337 (elite). No significant independent researcher commentary or broad media coverage has been identified beyond the official Sonatype advisory and standard vulnerability database entries (Sonatype Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."