Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-7494

Nexus Repository 3 is vulnerable to Server-Side Request Forgery (SSRF) via the SSL Certificate Retrieval endpoint. A user holding the nexus:ssl-truststore:read permission could cause the server to initiate outbound connections to internal or otherwise restricted network hosts. This issue affects Nexus Repository 3.0.0 through versions prior to 3.94.0.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 15.0%
CVSS Severity
CVSS v3 Score 5.0
Products affected by CVE-2026-7494


Contact Us

Shodan ® - All rights reserved