PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-77121 Sonatype CVE debrief

A user account with permission to deploy artifacts to a hosted Maven repository could upload a POM file containing an oversized metadata field. This causes future attempts to list or browse that repository's components to permanently fail until an administrator repairs the underlying data. Only the targeted repository is affected; other repositories and overall server health remain unaffected.

Vendor
Sonatype
Product
Nexus Repository Manager
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-02
Original CVE updated
2026-09-29
Advisory published
2026-09-02
Advisory updated
2026-09-29

Who should care

Defenders responsible for Nexus Repository Manager instances, especially those with users who have artifact deployment permissions, should assess exposure and prioritize mitigation.

Why it matters

This vulnerability allows a user with artifact deployment permissions to upload a malicious POM file, causing permanent failures in listing or browsing repository components. Defenders should prioritize verifying and mitigating this issue in their Nexus Repository Manager instances.

  • Defenders must verify artifact deployment permissions and restrict them to only necessary users.
  • Defenders should monitor repository component listings and browsing for errors.
  • Defenders need to review and apply vendor-provided patches or updates.

Technical summary

A user account with permission to deploy artifacts to a hosted Maven repository could upload a POM file containing an oversized metadata field. This causes future attempts to list or browse that repository's components to permanently fail until an administrator repairs the underlying data. The vulnerability affects only the targeted repository, with other repositories and overall server health remaining unaffected. Defenders should prioritize verifying and mitigating this issue in their Nexus Repository Manager instances, especially those with users who have artifact deployment permissions.

Defensive priority

Defenders should prioritize verifying and mitigating this issue in their Nexus Repository Manager instances, especially those with users who have artifact deployment permissions.

Recommended defensive actions

  • Verify the Nexus Repository Manager instance for exposure to artifact deployment permissions
  • Restrict artifact deployment permissions to only necessary users
  • Monitor repository component listings and browsing for errors
  • Review and apply vendor-provided patches or updates
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Review compensating controls for exposed systems while remediation is scheduled and verified

Evidence notes

The CVE record and NVD entry provide details about the vulnerability, including its description, CVSS score, and affected versions. Defenders should verify artifact deployment permissions and restrict them to only necessary users. The CVE Program and NVD provide official records, while vendor advisories offer additional guidance. Evidence limits suggest focusing on confirmed affected scope and vendor guidance.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-77121 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-77121

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-77121 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-77121

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://help.sonatype.com/en/sonatype-nexus-repository-3-95-0-release-notes.html

    103e4ec9-0a87-450b-af77-479448ddef11 - Release Notes, Vendor Advisory

  • Source reference

    Unverified legacy reference

    URL: https://support.sonatype.com/hc/en-us/articles/54635665756691/

    103e4ec9-0a87-450b-af77-479448ddef11 - Permissions Required, Vendor Advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.