Sonatype: community verdicts
4 notable / known-exploited Sonatype CVEs the community has triaged.
ⓘ Not an exhaustive list: we focus on the findings that matter (exploited / notable). For every Sonatype CVE, see NVD ↗.
- CVE-2020-10199HIGH 8.8KEVEPSS 99%
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
- CVE-2019-7238CRIT 9.8KEVEPSS 77%
Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control.
- CVE-2026-3329HIGH 7.5Real · low riskEPSS 1%
A remote unauthenticated attacker may be able to conduct credential-guessing attacks against user accounts in Sonatype Nexus Repository via authentication endpoints.
- CVE-2026-10741MED 4.9EPSS 0%
Sonatype Nexus Repository Manager before 3.93.0 contains an authorization vulnerability in the proxy repository configuration that allows a delegated repository administrator to disclose stored upstream proxy credentials.