CVE-2025-9868EPSS p40.3%
CVE-2025-9868CVE-2025-9868
Description
Server-Side Request Forgery (SSRF) in the Remote Browser Plugin in Sonatype Nexus Repository 2.x up to and including 2.15.2 allows unauthenticated remote attackers to exfiltrate proxy repository credentials via crafted HTTP requests.
Scoring
| EPSS | 0.50% probability of exploitation · percentile 40.3% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-26 |