Stored Cross-Site Scripting Vulnerability in Nexus Repository by Sonatype
CVE-2026-17596
6.3MEDIUM
What is CVE-2026-17596?
Nexus Repository 3 has a vulnerability that allows stored cross-site scripting (XSS). This issue arises when a user with permissions to create or update blob stores inserts a blob store name containing malicious script content. This content can be executed in the browsers of users accessing the system health-check status, potentially leading to unauthorized actions or data exposure. The vulnerability has been addressed in version 3.95.0, and users are recommended to upgrade to this version to mitigate the risk.
Affected Version(s)
Nexus Repository 3 3.16.0 < 3.95.0
