CVE-2026-3048
Nexus Repository 3 - Improper LDAP Referral Handling
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
An authenticated administrator who configures or tests LDAP connectivity in Sonatype Nexus Repository Manager versions 3.0.0 through 3.91.1 may be able to initiate unintended server-side connections when interacting with a malicious LDAP server.
| CWE | CWE-502 CWE-918 |
| Vendor | sonatype |
| Product | nexus repository |
| Published | May 11, 2026 |
| Last Updated | May 11, 2026 |
Stay Ahead of the Next One
Get instant alerts for sonatype nexus repository
Be the first to know when new unknown vulnerabilities affecting sonatype nexus repository are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Sonatype / Nexus Repository
3.0.0 < 3.92.0
References
Credits
Icare (@Icare1337)