CVE-2026-17597
Last modified
CVE-2026-17597 is a medium-severity vulnerability rated 5.1/10 on the CVSS scale. Nexus Repository 3 contains a Server-Side Request Forgery (SSRF) vulnerability in the email configuration verification feature. A user holding the nexus:settings:update permission could submit arbitrary host and port values to the email test/verification endpoint, causing the server to attempt outbound network connections to internal or otherwise restricted network addresses.
Description
Nexus Repository 3 contains a Server-Side Request Forgery (SSRF) vulnerability in the email configuration verification feature. A user holding the nexus:settings:update permission could submit arbitrary host and port values to the email test/verification endpoint, causing the server to attempt outbound network connections to internal or otherwise restricted network addresses. Differences in the server's response could be used to infer whether internal hosts and ports are reachable. This issue affects Nexus Repository 3 CE/Pro versions up to and including 3.94.1, and is fixed in version 3.95.0.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Sonatype | Nexus Repository 3 | >= 3.0.0, < 3.95.0 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-17597?
How severe is CVE-2026-17597?
How do I fix CVE-2026-17597?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-17583The affected Thermo Fisher Applied Biosystems Genetic Analy…8.4
- CVE-2026-17592Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMB…
- CVE-2026-17593An account holding the nexus:settings:update permission in N…7.2
- CVE-2026-17594Nexus Repository 3 CE/Pro versions 3.0.0 through 3.94.x cont…8.2
- CVE-2026-17595Nexus Repository 3 did not fully sandbox JEXL expressions us…5.3
- CVE-2026-17596Nexus Repository 3 was found to be vulnerable to stored cros…6.3
- CVE-2026-17598Sonatype Nexus Repository 3 did not properly filter internal…5.3
- CVE-2026-17599Nexus Repository 3 contained an endpoint used to change the …6.9
- CVE-2026-1760A flaw was found in SoupServer. This HTTP request smuggling …5.3
- CVE-2026-17600Sonatype Nexus Repository 3 did not immediately terminate a …8.7
- CVE-2026-17601A user holding a permission to update privilege definitions …8.9
- CVE-2026-17603Nexus Repository 3 did not sufficiently restrict which Hikar…8.7
Are you affected by CVE-2026-17597?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
