CVE-2026-17596
Nexus Repository 3 - Stored Cross-Site Scripting (XSS) via Blob Store Name
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Nexus Repository 3 was found to be vulnerable to stored cross-site scripting (XSS). A user with the nexus:blobstores:create or nexus:blobstores:update permission could set a blob store name containing malicious script content, which would later execute in the browser of another user viewing system health-check status. This issue has been fixed in version 3.95.0.
| CWE | CWE-79 |
| Vendor | sonatype |
| Product | nexus repository 3 |
| Published | Aug 7, 2026 |
Stay Ahead of the Next One
Get instant alerts for sonatype nexus repository 3
Be the first to know when new unknown vulnerabilities affecting sonatype nexus repository 3 are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Sonatype / Nexus Repository 3
3.16.0 < 3.95.0
References
Credits
Yousif (s3c_krd)