Sonatype Inc.
First CVE: Mar 21, 2024Active for: 2 years
29
CVEs Published
More CVEs Published than 48% of tracked CNAs
9.7
Avg CVEs / Year
More Avg CVEs / Year than 53% of tracked CNAs
7.1
Avg CVSS Score
Higher Avg CVSS Score than 50% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Self-Reporting Analysis
Of all the CVEs published by Sonatype Inc. as a CNA, 13.8% affect products that Sonatype Inc. develops as a vendor.
13.8%
86.2%
Self-reported: 4Third-party: 25
Of all the CVEs published that affect products developed by Sonatype Inc., 8.7% are self-published by Sonatype Inc. as a CNA.
91.3%
Self-published: 4Published by other CNAs: 42
Trends Over Time
The number and severity of CVEs published by Sonatype Inc. over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 21, 2024
2 years ago
Most Recent CVE
Jul 14, 2026
10 days ago
Top CVEs
All CVEs published by Sonatype Inc. as a CNA, regardless of affected vendor or product.
29 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-4956HIGH Path Traversal in Sonatype Nexus Repository 3 allows an unauthenticated attacker to read system files. Fixed in version 3.68.1. | May 16, 2024 | 7.5 | 55 | NO | YES |
CVE-2026-11403HIGH A vulnerability in Sonatype Nexus Repository Manager's format-specific API key generation may allow a remote attacker to gain unauthorized access to repository operations as a targ | Jul 14, 2026 | 8.7 | 35 | NO | NO |
CVE-2024-5082HIGH A Remote Code Execution vulnerability has been discovered in Sonatype Nexus Repository 2.
This issue affects Nexus Repository 2 OSS/Pro versions up to and including 2.15.1. | Nov 14, 2024 | 7.1 | 33 | NO | YES |
CVE-2026-14504HIGH An authorization bypass in Nexus Repository 3's component upload API allowed a user with only read/browse privileges on a Swift, Terraform, or Conda hosted repository to upload arb | Jul 14, 2026 | 8.2 | 32 | NO | NO |
CVE-2026-3199CRITICAL A vulnerability in the task management component of Sonatype Nexus Repository versions 3.22.1 through 3.90.2 allows an authenticated attacker with task creation permissions to exec | Apr 8, 2026 | 9.4 | 32 | NO | NO |
CVE-2025-12183HIGH Out-of-bounds memory operations in org.lz4:lz4-java 1.8.0 and earlier allow remote attackers to cause denial of service and read adjacent memory via untrusted compressed input. | Nov 28, 2025 | 8.8 | 31 | NO | NO |
CVE-2026-10748HIGH An authenticated user with the nx-licensing-create privilege can upload a specially crafted license file to execute arbitrary operating system commands as the Nexus process user in | Jun 16, 2026 | 8.6 | 30 | NO | NO |
CVE-2026-5189CRITICAL CWE-798: Use of Hard-coded Credentials in Sonatype Nexus Repository Manager versions 3.0.0 through 3.70.5 allows an unauthenticated attacker with network access to gain unauthorize | Apr 15, 2026 | 9.2 | 30 | NO | NO |
CVE-2025-13158CRITICAL Prototype pollution vulnerability in apidoc-core versions 0.2.0 and all subsequent versions allows remote attackers to modify JavaScript object prototypes via malformed data struct | Dec 26, 2025 | 9.3 | 30 | NO | NO |
CVE-2026-3329HIGH A remote unauthenticated attacker may be able to conduct credential-guessing attacks against user accounts in Sonatype Nexus Repository via authentication endpoints. | Jun 11, 2026 | 7.5 | 28 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA29 CVEs
48%
28%
24%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (3.4%)
Network28 (96.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low29 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None23 (79.3%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low8 (27.6%)
High6 (20.7%)
None15 (51.7%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (29 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
6.9% of CVEs· 94th percentile
ExploitDB
1 CVE
3.4% of CVEs· 92nd percentile
Social Chatter
An overview of all social media posts that mention a CVE ID published by Sonatype Inc. as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Sonatype Inc. as a CNA — matched by CVE ID, not by organization name.