CVE-2026-77121
Received Received - Intake

Maven Repository POM Metadata Field Overflow

Vulnerability report for CVE-2026-77121, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-02

Last updated on: 2026-09-02

Assigner: Sonatype

Description

A user account with permission to deploy artifacts to a hosted Maven repository could upload a POM file containing an oversized metadata field. This causes future attempts to list or browse that repository's components to permanently fail until an administrator repairs the underlying data. Only the targeted repository is affected; other repositories and overall server health remain unaffected.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-02
Last Modified
2026-09-02
Generated
2026-09-02
AI Q&A
2026-09-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
sonatype nexus_repository From 3.26 (inc) to 3.95.0 (exc)
sonatype nexus_repository 3.95

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-77121 is a Denial of Service (DoS) vulnerability in Sonatype Nexus Repository 3 versions 3.26 through 3.94.x. A user with deployment permissions can upload a Maven POM file with an oversized metadata field to a hosted repository. This causes the repository's component listing and browse functions to fail permanently, requiring admin repair.

Detection Guidance

Check Nexus Repository logs for failed component listing or browse attempts in hosted Maven repositories. Look for POM files with unusually large metadata fields. Use Nexus Repository admin interface to inspect repository health and component browsing functionality.

Impact Analysis

If exploited, this vulnerability disrupts access to a specific repository's components, preventing users from listing or browsing artifacts. This can halt development workflows dependent on that repository. Only the targeted repository is affected; other repositories and server health remain intact.

Compliance Impact

This vulnerability could impact compliance with GDPR and HIPAA by disrupting repository functionality, potentially leading to unauthorized data access or loss of audit trails if repository operations fail. However, the primary impact is operational disruption rather than direct data exposure.

Mitigation Strategies

Upgrade Nexus Repository to version 3.95.0 or later immediately. Temporarily restrict deployment permissions for users until the upgrade is complete. Monitor affected repositories for persistent failures and prepare for administrator intervention if corruption occurs.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-77121. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart