Intel

AIKIDO-2026-182141

sonatype-nexus-repository is vulnerable to Brute Force

Brute ForceCVE-2026-3329 Published 2 days ago

87

High Risk

This Affects:

JAVAsonatype-nexus-repository
3.0.0 - 3.92.3
Fixed in 3.93.0
Are you affected? Scan for Free

TL;DR

Sonatype Nexus Repository authentication endpoints for the UI and REST API do not restrict or throttle repeated failed login attempts. A remote unauthenticated attacker with network access to those endpoints can run unlimited credential-guessing or credential-stuffing attacks against user accounts and, on success, gain unauthorized access to artifacts, configuration, and stored credentials. The fix introduces authentication attempt rate limiting that returns HTTP 429 with a Retry-After header after consecutive failures, configurable via nexus.auth.ratelimit.* properties.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and expose Nexus Repository authentication endpoints over the network.

Background info

sonatype-nexus-repository is vulnerable to Brute Force in versions 3.0.0 - 3.92.3.

How to fix this

Upgrade the com.sonatype.nexus.selfhosted.distributions:sonatype-nexus-repository library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform