CVE-2026-14646

Nexus Repository 3 did not apply its existing Server-Side Request Forgery (SSRF) protections to HTTP redirect targets returned by proxy repository upstream servers. Any user with read access to a proxy repository backed by an attacker-controlled or compromised upstream server — including an anonymous user, if anonymous access is enabled — could receive a response from an internal network address or cloud metadata endpoint as repository content, potentially exposing sensitive information such as cloud IAM credentials.
CVSS

No CVSS.

Configurations

No configuration.

History

14 Jul 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-14 17:16

Updated : 2026-07-15 20:08


NVD link : CVE-2026-14646

Mitre link : CVE-2026-14646

CVE.ORG link : CVE-2026-14646


JSON object : View

Products Affected

No product.

CWE
CWE-918

Server-Side Request Forgery (SSRF)