SB2026090752 - Allocation of Resources Without Limits or Throttling in Nexus Repository Manager



SB2026090752 - Allocation of Resources Without Limits or Throttling in Nexus Repository Manager

Published: September 7, 2026

Security Bulletin ID SB2026090752
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Partial DoS

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Allocation of Resources Without Limits or Throttling (CVE-ID: CVE-2026-77121)

CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to cause a denial of service in repository component listing and browsing functionality.

The vulnerability exists due to allocation of resources without limits or throttling in Maven POM metadata field handling when processing an uploaded POM file containing an oversized metadata field. A remote user can upload a POM file containing an oversized metadata field to cause a denial of service in repository component listing and browsing functionality.

Only the targeted repository is affected; other repositories and overall server health remain unaffected.


Remediation

Install update from vendor's website.