Skip to main content
Sonatype Support Help Center home page My Sonatype
Community
Forum Ideas Office Hours Innovate
Learn
Courses Videos
Support
Knowledge Base Documentation
Resources
SSC Maturity Survey STEPP Assessment Hosted Workshops
Sign In Submit a request Sign In

Forum Ideas Office Hours Innovate
Courses Videos
Knowledge Base Documentation
SSC Maturity Survey STEPP Assessment Hosted Workshops
  1. Sonatype Support
  2. Announcements

Announcements

Announcements

  • PostgreSQL Index Corruption - "duplicate key violation" errors
  • Sonatype Data Services (HDS) Regularly Scheduled Maintenance
  • IQ Server vulnerability information contains the Root Cause
  • codehaus.org Repositories Should Be Removed From Your Nexus Repository Instance
  • Log4Shell log4j Vulnerability CVE-2021-44228 Status
  • Spring Framework RCE Vulnerability CVE-2021-22963 and SONATYPE-2022-1764
See all 7 articles

Security Advisories

  • CVE-2026-77125 Nexus Repository 3 - Incorrect Authorization on Blobstore Group Endpoints - 2026-09-02
  • CVE-2026-77124 Nexus Repository 3 - Script Execution Disable Setting Not Enforced - 2026-09-02
  • CVE-2026-77123 Nexus Repository 3 - Webhook Secret Disclosure via Capability Read API - 2026-09-02
  • CVE-2026-77122 Nexus Repository 3 - Authorization Bypass Exposes Member Repository Metadata - 2026-09-02
  • CVE-2026-77121 Nexus Repository 3 - Denial of Service via Unbounded Maven POM Metadata Fields - 2026-09-02
  • CVE-2026-17603 Nexus Repository 3 - HikariCP connectionInitSql Injection RCE via DataStore Configuration API - 2026-08-07
See all 68 articles
Terms of Service Privacy Policy Cookie Preferences
Copyright © 2008-present, Sonatype Inc. All rights reserved. Includes the third-party code listed here. Sonatype and Sonatype Nexus are trademarks of Sonatype, Inc. Apache Maven and Maven are trademarks of the Apache Software Foundation. M2Eclipse is a trademark of the Eclipse Foundation. All other trademarks are the property of their respective owners.