PatchSiren cyber security CVE debrief
CVE-2026-14646 Sonatype CVE debrief
A vulnerability in Nexus Repository 3 allows users with read access to a proxy repository to potentially expose sensitive information such as cloud IAM credentials by receiving responses from internal network addresses or cloud metadata endpoints as repository content. The vulnerability arises from the lack of Server-Side Request Forgery (SSRF) protections for HTTP redirect targets returned by proxy repository upstream servers. This could lead to unauthorized access to internal network addresses or cloud metadata endpoints, potentially exposing sensitive information. Defenders and administrators of Nexus Repository 3 instances should assess exposure and prioritize verification and
- Vendor
- Sonatype
- Product
- Nexus Repository Manager
- CVSS
- MEDIUM 4.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-14
- Original CVE updated
- 2026-09-22
- Advisory published
- 2026-07-14
- Advisory updated
- 2026-09-22
Who should care
Defenders and administrators of Nexus Repository 3 instances, especially those with users having read access to proxy repositories, should assess exposure and prioritize verification and potential remediation.
Why it matters
Defenders should prioritize verifying exposure, especially for users with read access to proxy repositories, and assess the need for compensating controls or monitoring due to the potential for sensitive information exposure.
- Potential exposure of sensitive information such as cloud IAM credentials
- Possible unauthorized access to internal network addresses or cloud metadata endpoints
- Need for verification of user access controls and compensating controls or monitoring
- Potential for suspicious responses from internal network addresses or cloud metadata endpoints in repository content
Technical summary
Nexus Repository 3 did not apply its existing Server-Side Request Forgery (SSRF) protections to HTTP redirect targets returned by proxy repository upstream servers, potentially allowing users with read access to a proxy repository to receive responses from internal network addresses or cloud metadata endpoints as repository content. This vulnerability could lead to the exposure of sensitive information such as cloud IAM credentials. The affected product context indicates that the vulnerability is specific to Nexus Repository 3 instances with certain configurations, and defenders should assess their exposure based on their specific environment.
Defensive priority
Defenders should prioritize verifying exposure, especially for users with read access to proxy repositories, and assess the need for compensating controls or monitoring.
Recommended defensive actions
- Verify exposure by checking user access to proxy repositories and assessing the need for compensating controls or monitoring
- Review and update access controls for proxy repositories to prevent unauthorized access
- Monitor repository content for suspicious responses from internal network addresses or cloud metadata endpoints
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, including its description, CVSS score, and affected versions. The vulnerability was reported and verified through official channels, and the details were sourced from the CVE Program and NVD. The evidence is based on the information available up to the publication date of the CVE record. The source grounding indicates that the vulnerability affects Nexus Repository 3 instances with specific configurations, and defenders should verify their exposure based on their
Sources and references
Verified primary and authoritative sources
-
CVE-2026-14646 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-14646
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-14646 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-14646
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://help.sonatype.com/en/sonatype-nexus-repository-3-94-0-release-notes.html
103e4ec9-0a87-450b-af77-479448ddef11 - Permissions Required
-
Source reference
Unverified legacy reference
URL: https://support.sonatype.com/hc/en-us/articles/53165019641363/
103e4ec9-0a87-450b-af77-479448ddef11 - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.