Skip to main content
Sonatype Support Help Center home page My Sonatype
Community
Forum Ideas Office Hours Innovate
Learn
Courses Videos
Support
Knowledge Base Documentation
Resources
SSC Maturity Survey STEPP Assessment Hosted Workshops
Sign In Submit a request Sign In

Forum Ideas Office Hours Innovate
Courses Videos
Knowledge Base Documentation
SSC Maturity Survey STEPP Assessment Hosted Workshops
  1. Sonatype Support
  2. Announcements

Announcements

Announcements

  • PostgreSQL Index Corruption - "duplicate key violation" errors
  • Sonatype Data Services (HDS) Regularly Scheduled Maintenance
  • IQ Server vulnerability information contains the Root Cause
  • codehaus.org Repositories Should Be Removed From Your Nexus Repository Instance
  • Log4Shell log4j Vulnerability CVE-2021-44228 Status
  • Spring Framework RCE Vulnerability CVE-2021-22963 and SONATYPE-2022-1764
See all 7 articles

Security Advisories

  • CVE-2026-17603 Nexus Repository 3 - HikariCP connectionInitSql Injection RCE via DataStore Configuration API - 2026-08-07
  • CVE-2026-17601 Nexus Repository 3 - Wildcard Privilege Update Self-Escalation to Administrator - 2026-08-07
  • CVE-2026-17600 Nexus Repository 3 - Session Not Invalidated on Account Deletion or Deactivation - 2026-08-07
  • CVE-2026-17599 Nexus Repository 3 - Unverified Onboarding State on change-admin-password Endpoint - 2026-08-07
  • CVE-2026-17598 Nexus Repository 3 - Improper Input Validation in Scheduled Task Configuration - 2026-08-07
  • CVE-2026-17597 Nexus Repository 3 - SSRF via Email Configuration Verification - 2026-08-07
See all 63 articles
Terms of Service Privacy Policy Cookie Preferences
Copyright © 2008-present, Sonatype Inc. All rights reserved. Includes the third-party code listed here. Sonatype and Sonatype Nexus are trademarks of Sonatype, Inc. Apache Maven and Maven are trademarks of the Apache Software Foundation. M2Eclipse is a trademark of the Eclipse Foundation. All other trademarks are the property of their respective owners.