#VU121281 Server-Side Request Forgery (SSRF) in Nexus Repository Manager - CVE-2026-0600
Published: January 13, 2026
Nexus Repository Manager
Sonatype Inc.
Description
The disclosed vulnerability allows a remote user to perform SSRF attacks.
The vulnerability exists due to insufficient validation of user-supplied input. A remote administrator can configure a proxy repository with a remote storage URL that, when accessed by users, allows the server to make requests to unintended network destinations including cloud metadata services and internal networks.