CVE-2026-14645 Details
Description
Nexus Repository 3 does not validate the destination of the "Webhook: Global" capability's configured URL before making an outbound HTTP request, allowing a user holding the Capability Administration permission to cause the server to send requests to internal network locations (Server-Side Request Forgery). This permission is granted by role assignment, independent of authentication status, so an unauthenticated user could also trigger this behavior if the anonymous role has been granted the permission.
A server-side request forgery (SSRF) vulnerability has been identified in Sonatype Nexus Repository 3. This issue arises because the application does not validate the destination URL of the 'Webhook: Global' capability before sending outbound HTTP requests. As a result, a user with Capability Administration permission can configure a URL that points to internal network locations, causing the server to send requests to those targets. This vulnerability can be exploited by unauthenticated users if the anonymous role has been granted the necessary permission.
Users are advised to upgrade to Sonatype Nexus Repository 3 CE/Pro version 3.94.0 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://help.sonatype.com/en/sonatype-nexus-repository-3-94-0-release-notes.html | Sonatype | Release Notes |
| https://support.sonatype.com/hc/en-us/articles/53158843564179/ | Sonatype | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | Sonatype |
Affected Products
| Product | Versions |
|---|---|
| sonatype nexus repository manager | >= 3.0.0, < 3.94.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 22, 2026 | Reanalysis | [email protected] |
| Sep 22, 2026 | Initial Analysis | [email protected] |
| Jul 15, 2026 | CVE Modified | CISA-ADP |
| Jul 14, 2026 | New CVE Received | Sonatype |