Sonatype
CVE Numbering Authority
Latest CVE published
Overview
Sonatype is a CVE Numbering Authority that has published 16 CVE records since 2024. It is currently classified as active, with 16 CVEs published in the last two years. Its CVE data quality is graded A (96.9% overall completeness).
Among the 370 CNAs tracked here, Sonatype ranks #268 by CVE volume and reports more complete records than 46% of all CNAs.
Data quality report card
How complete and consistent Sonatype's CVE records are, scored across vendor, product, CVSS, and CWE coverage.
A CVE record only requires a description to be published. “Completeness” measures how often Sonatype also fills in the optional — but extremely useful — fields that make a vulnerability actually actionable: the affected vendor and product, a CVSS severity score, and a CWE weakness type. A higher score means more of this CNA’s CVEs include those details, so defenders spend less time enriching records by hand.
Report card grade
96.9%
Overall score
What these scores mean
- Vendor completeness
- The share of this CNA's CVEs that name an affected vendor.
- Product completeness
- The share that name a specific affected product.
- CVSS completeness
- The share that include a CVSS severity score.
- CWE completeness
- The share mapped to a CWE weakness type.
- Update rate
- How often this CNA revises CVE records after first publishing them.
- Vendor diversity
- How many distinct vendors this CNA publishes CVEs for.
Severity and exploitation
How the CVSS severity of Sonatype's published CVEs breaks down, and how many are known to be exploited in the wild.
In CISA’s Known Exploited Vulnerabilities catalog
0
None of Sonatype's CVEs are currently listed in CISA's Known Exploited Vulnerabilities catalog.
Common weakness types
The CWE weakness categories Sonatype most often assigns to its CVEs. Follow any weakness to its full explanation.
- CWE-918Server-Side Request Forgery (SSRF)7 CVEs
- CWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')6 CVEs
- CWE-863Incorrect Authorization2 CVEs
- CWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2 CVEs
- CWE-862Missing Authorization2 CVEs
- CWE-345Insufficient Verification of Data Authenticity2 CVEs
- CWE-502Deserialization of Untrusted Data2 CVEs
- CWE-798Use of Hard-coded Credentials2 CVEs
Publishing activity by year
How many CVEs Sonatype has published each year.
Top vendors
The vendors Sonatype publishes the most CVEs for.
Top products
The products Sonatype publishes the most CVEs for.
- Nexus Repository16 CVEs
- Nexus Repository 313 CVEs
- Nexus Repository Manager4 CVEs
- picklescan4 CVEs
- nexus-public3 CVEs
- IQ Server1 CVEs
- net.jpountz.lz4:lz41 CVEs
- Nexus Repository 2.x1 CVEs
Latest CVEs
The most recent CVEs assigned by Sonatype.
- CVE-2026-14644CWE-843
Nexus Repository 3 - Privilege Escalation
High · CVSS 8.6EPSS 0.2%2026-08-07 - CVE-2026-17593CWE-470
Nexus Repository - Arbitrary Class Instantiation via Unsafe Realm Configuration
High · CVSS 7.2EPSS 0.3%2026-08-07 - CVE-2026-17594CWE-863
Nexus Repository 3 - Authorization Bypass in Repository Creation
High · CVSS 8.2EPSS 0.6%2026-08-07 - CVE-2026-17595CWE-497
Nexus Repository 3 - JEXL Content Selector Sandbox Property-Read Bypass
Medium · CVSS 5.3EPSS 0.3%2026-08-07 - CVE-2026-17596CWE-79
Nexus Repository 3 - Stored Cross-Site Scripting (XSS) via Blob Store Name
Medium · CVSS 6.3EPSS 0.2%2026-08-07 - CVE-2026-17598CWE-915
Nexus Repository 3 - Improper Input Validation in Scheduled Task Configuration
Medium · CVSS 5.3EPSS 0.3%2026-08-07 - CVE-2026-17599CWE-620
Nexus Repository 3 - Unverified Onboarding State on change-admin-password Endpoint
Medium · CVSS 6.9EPSS 0.3%2026-08-07 - CVE-2026-17600CWE-613
Nexus Repository 3 - Session Not Invalidated on User Account Deletion or Deactivation
High · CVSS 8.7EPSS 0.2%2026-08-07 - CVE-2026-17601CWE-862
Nexus Repository 3 - Wildcard Privilege Update Self-Escalation to Administrator
High · CVSS 8.9EPSS 0.2%2026-08-07 - CVE-2026-17603CWE-94
Nexus Repository 3 - HikariCP connectionInitSql Injection RCE via DataStore Configuration API
High · CVSS 8.7EPSS 0.4%2026-08-07 - CVE-2026-17597CWE-918
Nexus Repository 3 - Server-Side Request Forgery via Email Configuration Verification
Medium · CVSS 5.1EPSS 0.3%2026-08-07 - CVE-2026-14646CWE-918
Nexus Repository 3 - Server-Side Request Forgery (SSRF) via HTTP Redirect
Medium · CVSS 4.9EPSS 0.3%2026-07-14
Track new Sonatype CVEs as they are published and get AI-written analysis and remediation guidance.
Monitor Sonatype CVEsOther CNAs
Compare data quality across other CVE Numbering Authorities.
Frequently asked questions
Common questions about the Sonatype CNA.
- What is the Sonatype CNA?
- Sonatype is a CVE Numbering Authority (CNA) — an organization authorized to assign CVE IDs to vulnerabilities in its scope. It has published 16 CVE records since 2024.
- How many CVEs has Sonatype published?
- Sonatype has published 16 CVE records, including 16 in the last two years.
- What is Sonatype's CVE data quality grade?
- RadicalNotion.AI grades Sonatype's CVE data quality as A, with an overall completeness score of 96.9%. This reflects how consistently its CVE records include vendor (93.8%), product (93.8%), CVSS (100%), and CWE (100%) information.
- What products does Sonatype publish CVEs for?
- Sonatype most frequently publishes CVEs for Nexus Repository, Nexus Repository 3, Nexus Repository Manager, picklescan, nexus-public.
- Which vendors does Sonatype cover?
- Sonatype publishes CVEs across 5 distinct vendors, most often Sonatype, PyPI, mmaitre314, yawkat, phlocbg.
- Is Sonatype actively publishing CVEs?
- Sonatype is currently active, based on 16 CVEs in the last two years.
- What is the average severity of Sonatype's CVEs?
- The average CVSS base score across Sonatype's scored CVEs is 6.5.
- How many critical CVEs has Sonatype published?
- Sonatype has published 4 critical-severity CVEs and 14 high-severity CVEs.
- Are any of Sonatype's CVEs in CISA's Known Exploited Vulnerabilities catalog?
- No. None of Sonatype's CVEs are currently listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.
- What are the most common weakness types in Sonatype's CVEs?
- Sonatype's CVEs most often map to these CWE weakness types: CWE-918 (Server-Side Request Forgery (SSRF)), CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')), CWE-863 (Incorrect Authorization), CWE-22 (Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')).
- How does Sonatype rank among CNAs?
- By total CVE volume, Sonatype ranks #268 of 370 CNAs, and it reports more complete CVE records than 46% of all CNAs.
References
- Official CVE.org list of CNA partners (opens in a new tab)
- Learn: What is a CNA?
- CWE directory: the weakness types this CNA maps its CVEs to
CNA report-card grades are computed by RadicalNotion.AI from published CVE records. CVE data is sourced from the CVE Program.
Track Sonatype CVEs
Monitor new vulnerabilities as this CNA publishes them, with AI-written analysis and remediation guidance.