Credential Exposure in Dependency-Track by Dependency-Track
CVE-2025-61776
What is CVE-2025-61776?
Prior to version 4.13.5, Dependency-Track may inadvertently expose credentials intended for private NuGet repositories by sending them to api.nuget.org through the HTTP Authorization header. This may occur if the Dependency-Track instance incorporates .NET components, uses a custom NuGet repository with authentication, and the repository server lacks a PackageBaseAddress in its service index. Users are advised to disable custom NuGet repositories until the patch is applied, revoke previously used credentials, and generate new ones for future use post-patch.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
dependency-track < 4.13.5
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
