PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-3438 Sonatype CVE debrief

A reflected cross-site scripting vulnerability exists in Sonatype Nexus Repository versions 3.0.0 through 3.90.2. This vulnerability allows unauthenticated remote attackers to execute arbitrary JavaScript in a victim's browser through a specially crafted URL. Exploitation requires user interaction. The vulnerability has a CVSS score of 5.1 and is classified as MEDIUM severity. The CVE record was published on 2026-04-08T23:16:59.410Z and has not been modified since then.

Vendor
Sonatype
Product
Nexus Repository
CVSS
MEDIUM 5.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-08
Original CVE updated
2026-07-24
Advisory published
2026-04-08
Advisory updated
2026-07-24

Who should care

Users of Sonatype Nexus Repository versions 3.0.0 through 3.90.2 should be aware of this vulnerability and take steps to mitigate it. This includes inventorying and checking for vulnerable versions, applying vendor remediation when available, implementing compensating controls such as web application firewalls, monitoring for suspicious activity, and tracking exceptions and retesting remediated assets.

Technical summary

The vulnerability is a reflected cross-site scripting (XSS) issue in Sonatype Nexus Repository versions 3.0.0 through 3.90.2. An attacker can craft a URL that, when visited by a victim, will execute arbitrary JavaScript in the victim's browser. This requires user interaction, as the victim must click on the crafted link. The vulnerability affects Sonatype Nexus Repository versions 3.0.0 through 3.90.2 and has a CVSS score of 5.1, classified as MEDIUM severity. Users should verify the information with official sources for the most up-to-date details and consider compensating controls such as web application firewalls.

Defensive priority

Medium priority due to the CVSS score of 5.1 and the potential for user interaction.

Recommended defensive actions

  • Inventory and check for vulnerable Sonatype Nexus Repository versions
  • Apply vendor remediation when available
  • Implement compensating controls such as web application firewalls
  • Monitor for suspicious activity
  • Exception tracking and retest
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed

Evidence notes

The CVE record was published on 2026-04-08T23:16:59.410Z and was last modified on 2026-07-24T22:10:00.140Z. The NVD entry is currently Awaiting Analysis. This information is based on the provided source corpus and may not reflect the current status. Users should verify the information with the official sources for the most up-to-date details.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-08T23:16:59.410Z and has not been modified since then. The NVD entry is currently Awaiting Analysis.