CVE-2026-7494 UNKNOWN

CVE-2026-7494

Published: 2026-07-14

Description

Nexus Repository 3 is vulnerable to Server-Side Request Forgery (SSRF) via the SSL Certificate Retrieval endpoint. A user holding the nexus:ssl-truststore:read permission could cause the server to initiate outbound connections to internal or otherwise restricted network hosts. This issue affects Nexus Repository 3.0.0 through versions prior to 3.94.0.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…