SB2026090752 - Allocation of Resources Without Limits or Throttling in Nexus Repository Manager
Published: September 7, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Allocation of Resources Without Limits or Throttling (CVE-ID: CVE-2026-77121)
CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause a denial of service in repository component listing and browsing functionality.
The vulnerability exists due to allocation of resources without limits or throttling in Maven POM metadata field handling when processing an uploaded POM file containing an oversized metadata field. A remote user can upload a POM file containing an oversized metadata field to cause a denial of service in repository component listing and browsing functionality.
Only the targeted repository is affected; other repositories and overall server health remain unaffected.
Remediation
Install update from vendor's website.