Allocation of Resources Without Limits or Throttling in Nexus Repository Manager - CVE-2026-77121

 

Allocation of Resources Without Limits or Throttling in Nexus Repository Manager - CVE-2026-77121

Published: September 7, 2026


Vulnerability identifier: #VU147242
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-77121
CWE-ID: CWE-770
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to cause a denial of service in repository component listing and browsing functionality.

The vulnerability exists due to allocation of resources without limits or throttling in Maven POM metadata field handling when processing an uploaded POM file containing an oversized metadata field. A remote user can upload a POM file containing an oversized metadata field to cause a denial of service in repository component listing and browsing functionality.

Only the targeted repository is affected; other repositories and overall server health remain unaffected.


Affected software

Nexus Repository Manager

How to mitigate CVE-2026-77121

Install security update from vendor's website.

Nexus Repository Manager - update to 3.95.0-07

External References

Related Security Bulletins