CVE-2026-7494

Nexus Repository 3 is vulnerable to Server-Side Request Forgery (SSRF) via the SSL Certificate Retrieval endpoint. A user holding the nexus:ssl-truststore:read permission could cause the server to initiate outbound connections to internal or otherwise restricted network hosts. This issue affects Nexus Repository 3.0.0 through versions prior to 3.94.0.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-07-14 16:17

Updated : 2026-07-15 20:08


NVD link : CVE-2026-7494

Mitre link : CVE-2026-7494

CVE.ORG link : CVE-2026-7494


JSON object : View

Products Affected

No product.

CWE
CWE-918

Server-Side Request Forgery (SSRF)