CVE-2026-7494

Nexus Repository 3 is vulnerable to Server-Side Request Forgery (SSRF) via the SSL Certificate Retrieval endpoint. A user holding the nexus:ssl-truststore:read permission could cause the server to initiate outbound connections to internal or otherwise restricted network hosts. This issue affects Nexus Repository 3.0.0 through versions prior to 3.94.0.
CVSS

No CVSS.

Configurations

No configuration.

History

14 Jul 2026, 16:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-14 16:17

Updated : 2026-07-15 20:08


NVD link : CVE-2026-7494

Mitre link : CVE-2026-7494

CVE.ORG link : CVE-2026-7494


JSON object : View

Products Affected

No product.

CWE
CWE-918

Server-Side Request Forgery (SSRF)