Oversized Metadata Vulnerability in Sonatype Nexus Repository
CVE-2026-77121

5.3MEDIUM

Key Information:

Vendor

Sonatype

Vendor
CVE Published:
2 September 2026

What is CVE-2026-77121?

This vulnerability allows a user account with permission to deploy artifacts to a hosted Maven repository to upload a POM file that contains an oversized metadata field. This condition leads to failures in future attempts to list or browse components in the affected repository, requiring administrative intervention to rectify the underlying data. The issue is localized to the targeted repository, and other repositories as well as the overall server infrastructure remain unaffected.

Affected Version(s)

Nexus Repository 3 3.26.0 < 3.95.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

e0x1337 (elite)
.