CVE-2026-77121: Sonatype Nexus Repository Manager

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

A user account with permission to deploy artifacts to a hosted Maven repository could upload a POM file containing an oversized metadata field. This causes future attempts to list or browse that repository's components to permanently fail until an administrator repairs the underlying data. Only the targeted repository is affected; other repositories and overall server health remain unaffected.

Affected products

  • Sonatype Nexus Repository Manager: from 3.26.0, before 3.95.0 (fixed in 3.95.0)

Published 2026-09-02. Last modified 2026-10-07.