Sonatype Inc. develops a focused line of software supply-chain and repository-management products, primarily Nexus Repository Manager and Nexus IQ Server, that occupy a critical but specialized position in build and artifact-distribution pipelines across enterprise development environments. The vendor's vulnerability footprint, while limited in product breadth, appears among the more prominent in the landscape due to the depth and prevalence of these tools in continuous-integration infrastructure. Recurring exposure centers on web-application and access-control flaws—cross-site scripting, path traversal, expression-language injection, and authorization weaknesses—that reflect the complexity of repository parsing, plugin execution, and user-privilege management in a platform that handles both privileged build operations and external artifact sources. A meaningful share of vulnerabilities affecting this vendor reach serious severity, and defenders should treat disclosures for these products as high-priority because remediation delays create supply-chain ingress points. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sonatype Inc. over time
Of all the CVEs published by Sonatype Inc. as a CNA, 13.8% affect products that Sonatype Inc. develops as a vendor.
Of all the CVEs published that affect products developed by Sonatype Inc., 8.7% are self-published by Sonatype Inc. as a CNA.
Signals from CVEs in this vendor scope (46 CVEs).
46 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-10199HIGH Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2). | Apr 1, 2020 | 8.8 | 98 | YES | YES |
CVE-2019-7238CRITICAL Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control. | Mar 21, 2019 | 9.8 | 95 | YES | YES |
CVE-2019-5475HIGH The Nexus Yum Repository Plugin in v2 is vulnerable to Remote Code Execution when instances using CommandLineExecutor.java are supplied vulnerable data, such as the Yum Configurati | Sep 3, 2019 | 8.8 | 37 | NO | NO |
CVE-2020-10204HIGH Sonatype Nexus Repository before 3.21.2 allows Remote Code Execution. | Apr 1, 2020 | 7.2 | 36 | NO | NO |
CVE-2026-11403HIGH A vulnerability in Sonatype Nexus Repository Manager's format-specific API key generation may allow a remote attacker to gain unauthorized access to repository operations as a targ | Jul 14, 2026 | 8.7 | 35 | NO | NO |
CVE-2021-37152MEDIUM Multiple XSS issues exist in Sonatype Nexus Repository Manager 3 before 3.33.0. An authenticated attacker with the ability to add HTML files to a repository could redirect users to | Aug 10, 2021 | 5.4 | 30 | NO | NO |
CVE-2020-15012HIGH A Directory Traversal issue was discovered in Sonatype Nexus Repository Manager 2.x before 2.14.19. A user that requests a crafted path can traverse up the file system to get acces | Oct 12, 2020 | 8.6 | 29 | NO | NO |
CVE-2017-17717CRITICAL Sonatype Nexus Repository Manager through 2.14.5 has weak password encryption with a hardcoded CMMDwoV value in the LDAP integration feature. | Dec 17, 2017 | 9.8 | 29 | NO | NO |
CVE-2026-3329HIGH A remote unauthenticated attacker may be able to conduct credential-guessing attacks against user accounts in Sonatype Nexus Repository via authentication endpoints. | Jun 11, 2026 | 7.5 | 28 | NO | NO |
CVE-2021-40143HIGH Sonatype Nexus Repository 3.x through 3.33.1-01 is vulnerable to an HTTP header injection. By sending a crafted HTTP request, a remote attacker may disclose sensitive information o | Sep 7, 2021 | 8.2 | 26 | NO | NO |
Signals from CVEs in this vendor scope (46 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sonatype Inc..
Media articles that mention a CVE ID that affects a product developed by Sonatype Inc. — matched by CVE ID, not by vendor name.