Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-14646

Nexus Repository 3 did not apply its existing Server-Side Request Forgery (SSRF) protections to HTTP redirect targets returned by proxy repository upstream servers. Any user with read access to a proxy repository backed by an attacker-controlled or compromised upstream server — including an anonymous user, if anonymous access is enabled — could receive a response from an internal network address or cloud metadata endpoint as repository content, potentially exposing sensitive information such as cloud IAM credentials.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 25.0%
CVSS Severity
CVSS v3 Score 7.7
Products affected by CVE-2026-14646


Contact Us

Shodan ® - All rights reserved