CVE-2026-17595

Source
https://cve.org/CVERecord?id=CVE-2026-17595
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-17595.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-17595
Downstream
MINI (2)
Published
2026-08-07T16:07:43Z
Modified
2026-09-24T03:45:13Z
Severity
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Nexus Repository 3 - JEXL Content Selector Sandbox Property-Read Bypass
Details

Nexus Repository 3 did not fully sandbox JEXL expressions used in Content Selectors. An account holding the nexus:selectors:create permission could construct an expression that read Java object properties not intended to be exposed to the expression engine, disclosing internal JVM class metadata such as class and classloader names. This issue does not permit method invocation, object construction, or arbitrary code execution. This has been fixed by restricting property access in the JEXL sandbox to the intended data types.

Database specific
{
    "cna_assigner":  "Sonatype",
    "cwe_ids":  [
        "CWE-497"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/17xxx/CVE-2026-17595.json",
    "unresolved_ranges":  [
        {
            "extracted_events":  [
                {
                    "introduced":  "3.15.0"
                },
                {
                    "fixed":  "3.95.0"
                }
            ],
            "source":  "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/sonatype/nexus-public

Affected ranges

Type
GIT
Repo
https://github.com/sonatype/nexus-public
Events
Database specific
Show details
{
    "cpe":  "cpe:2.3:a:sonatype:nexus_repository_manager:*:*:*:*:*:*:*:*",
    "extracted_events":  [
        {
            "introduced":  "3.15.0"
        },
        {
            "fixed":  "3.95.0"
        }
    ],
    "source":  "CPE_RANGE"
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-17595.json"