- CVE ID
- CVE-2026-17596
- CVE Description
- Nexus Repository 3 was found to be vulnerable to stored cross-site scripting (XSS). A user with the nexus:blobstores:create or nexus:blobstores:update permission could set a blob store name containing malicious script content, which would later execute in the browser of another user viewing system health-check status. This issue has been fixed in version 3.95.0.
- Published
- Jul 28, 2026
- CVSS Score & Severity
6.1Medium
- CVSS Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS Score
- 0.237%
- KEV Status
Not in KEV Catalog: No known exploits
- Vulnerable Methods
org/sonatype/nexus/blobstore/quota/internal/SpaceRemainingQuota.check(Lorg/sonatype/nexus/blobstore/api/BlobStore;)Lorg/sonatype/nexus/blobstore/quota/BlobStoreQuotaResult;JVMVulnerable params: 0
org/sonatype/nexus/repository/internal/blobstore/BlobStoreStateHealthCheck.check()Lcom/codahale/metrics/health/HealthCheck$Result;JVM
- Source
- National Vulnerability Database