CVE-2026-14646
Sonatype Nexus 3 vulnerability analysis and mitigation

Overview

CVE-2026-14646 is a Server-Side Request Forgery (SSRF) vulnerability in Sonatype Nexus Repository 3 that allows SSRF protections to be bypassed via HTTP redirect targets returned by proxy repository upstream servers. It affects all Nexus Repository 3 CE/Pro versions from 3.0.0 through 3.93.x, and was disclosed on July 14, 2026. The vulnerability was assigned a CVSS v4.0 base score of 4.9 (Medium) by Sonatype (Sonatype Advisory, Sonatype Release Notes).

Technical details

The root cause is classified as CWE-918 (Server-Side Request Forgery), specifically that Nexus Repository 3 failed to apply its existing SSRF protections to HTTP redirect targets returned by proxy repository upstream servers. When a proxy repository's upstream server returns an HTTP redirect, Nexus follows the redirect without validating the destination against its SSRF blocklist, allowing the redirect to point to internal network addresses or cloud metadata endpoints (e.g., http://169.254.169.254/). Exploitation requires that the attacker control or compromise the upstream server configured for a proxy repository, and that the requesting user (including anonymous users if anonymous access is enabled) has read access to that proxy repository (Sonatype Advisory).

Impact

Successful exploitation allows an attacker to cause Nexus Repository to fetch and return content from internal network addresses or cloud metadata endpoints as repository content to the requesting user. The most significant risk is exposure of sensitive information such as cloud IAM credentials (e.g., AWS instance metadata at 169.254.169.254), which could enable lateral movement within cloud environments or privilege escalation. Confidentiality and availability of the Nexus instance itself are not directly impacted, but the integrity of the broader cloud environment may be compromised through credential theft (Sonatype Advisory).

Exploitability

No public proof-of-concept exploit code or in-the-wild exploitation has been reported as of the disclosure date. CISA's SSVC assessment classifies exploitation as "none" and the vulnerability as not automatable, with only partial technical impact (Feedly). The EPSS score is approximately 0.265%, indicating a low probability of exploitation in the near term. The vulnerability was discovered and responsibly disclosed by researcher e0x1337 (elite) via Sonatype's Bug Bounty Program, and it is not listed in the CISA KEV catalog (Sonatype Advisory).

Exploitation steps

  1. Establish upstream control: The attacker must control or compromise a server that is configured as the upstream for a Nexus Repository 3 proxy repository (e.g., a malicious or compromised package registry).
  2. Craft a redirect response: Configure the attacker-controlled upstream server to respond to artifact requests with an HTTP redirect (301/302) pointing to an internal network address or cloud metadata endpoint, such as http://169.254.169.254/latest/meta-data/iam/security-credentials/.
  3. Trigger a proxy request: As any user with read access to the affected proxy repository (including anonymous users if anonymous access is enabled), request an artifact from the Nexus proxy repository that will be fetched from the malicious upstream.
  4. Receive internal response: Nexus Repository follows the redirect without applying SSRF protections, fetches the content from the internal/metadata endpoint, and returns it to the requesting user as repository content — potentially exposing cloud IAM credentials or other sensitive internal data (Sonatype Advisory).

Indicators of compromise

  • Network: Outbound HTTP requests from the Nexus Repository server to cloud metadata IP addresses (e.g., 169.254.169.254, fd00:ec2::254) or unexpected internal network ranges, particularly following requests to proxy repositories.
  • Logs: Nexus Repository access logs showing artifact fetch requests to proxy repositories backed by third-party or external upstream servers, followed by outbound connections to internal addresses; HTTP redirect chains in Nexus proxy request logs pointing to non-public destinations.
  • File System: Unexpected cached content in Nexus blob stores containing cloud metadata responses (e.g., JSON blobs with IAM credential fields such as AccessKeyId, SecretAccessKey, Token) rather than legitimate package artifacts.
  • Cloud/IAM: Unexpected API calls or authentication events using instance/IAM credentials shortly after Nexus proxy repository activity, which may indicate credential theft and misuse (Sonatype Advisory).

Mitigation and workarounds

Sonatype has released a fix in Nexus Repository 3 CE/Pro version 3.94.0 (released July 9, 2026); upgrading to this version or later is the recommended remediation (Sonatype Release Notes). As an immediate mitigation prior to upgrading, restrict proxy repository upstream configurations to trusted, known hosts and avoid enabling anonymous or broad read access on proxy repositories pointed at third-party or partner-controlled servers. If the Nexus instance runs in a cloud environment (AWS, GCP, Azure) and may have been exposed, Sonatype recommends rotating any instance/IAM credentials accessible via the cloud metadata service as a precaution (Sonatype Advisory).

Community reactions

Sonatype disclosed this vulnerability as part of a coordinated release of multiple Nexus Repository 3 security advisories on July 14, 2026, following responsible disclosure through their Bug Bounty Program. The vulnerability was credited to researcher e0x1337 (elite). No significant independent researcher commentary or broad media coverage has been identified beyond the official Sonatype advisory and standard vulnerability database entries (Sonatype Advisory).

Additional resources


SourceThis report was generated using AI

Related Sonatype Nexus 3 vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-17601HIGH8.9
  • Sonatype Nexus 3 logoSonatype Nexus 3
  • cpe:2.3:a:sonatype:nexus_repository_manager
NoYesAug 07, 2026
CVE-2026-17603HIGH8.7
  • Sonatype Nexus 3 logoSonatype Nexus 3
  • cpe:2.3:a:sonatype:nexus_repository_manager
NoYesAug 07, 2026
CVE-2026-17600HIGH8.7
  • Sonatype Nexus 3 logoSonatype Nexus 3
  • cpe:2.3:a:sonatype:nexus_repository_manager
NoYesAug 07, 2026
CVE-2026-17599MEDIUM6.9
  • Sonatype Nexus 3 logoSonatype Nexus 3
  • cpe:2.3:a:sonatype:nexus_repository_manager
NoYesAug 07, 2026
CVE-2026-17598MEDIUM5.3
  • Sonatype Nexus 3 logoSonatype Nexus 3
  • cpe:2.3:a:sonatype:nexus_repository_manager
NoYesAug 07, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management