Impact
The vulnerability allows an authenticated user with deploy permission to upload an oversized metadata field into a Maven POM file. Upon retrieval of the repository data, the oversized field causes the component listing and browsing operations to fail permanently. The failure is localized to the affected repository; other repositories and the overall server remain operational. The weakness arises from an inability to enforce size limits on input (CWE‑770).
Affected Systems
Affected products are Sonatype Nexus Repository 3 versions from 3.26.0 through 3.94.1, inclusive. Only these installations are vulnerable—other repository types and the host server are unaffected by the denial of service.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. No EPSS data is available, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be a local or remote authenticated upload via the repository's deployment API, requiring deployment privileges. Once exploited, the repository becomes unusable until an administrator repairs the corrupted metadata, creating a significant availability impact but no breach of confidentiality or integrity.
OpenCVE Enrichment