Allocation of Resources Without Limits or Throttling in Nexus Repository Manager - CVE-2026-77121
Published: September 7, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service in repository component listing and browsing functionality.
The vulnerability exists due to allocation of resources without limits or throttling in Maven POM metadata field handling when processing an uploaded POM file containing an oversized metadata field. A remote user can upload a POM file containing an oversized metadata field to cause a denial of service in repository component listing and browsing functionality.
Only the targeted repository is affected; other repositories and overall server health remain unaffected.