{"id":"CVE-2026-77121","title":"A user account with permission to deploy artifacts to a hosted Maven repository could upload a POM file containing an oversized metadata field","summary":"A user account with permission to deploy artifacts to a hosted Maven repository could upload a POM file containing an oversized metadata field. This causes future attempts to list or browse that repository's components to permanently fai…","severity":"none","cwe":["CWE-770"],"published":"2026-09-02","updated":"2026-09-08","sourceUpdated":"2026-09-08T19:20:25.117","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-77121","references":[{"url":"https://help.sonatype.com/en/sonatype-nexus-repository-3-95-0-release-notes.html","label":"103e4ec9-0a87-450b-af77-479448ddef11"},{"url":"https://support.sonatype.com/hc/en-us/articles/54635665756691/","label":"103e4ec9-0a87-450b-af77-479448ddef11"}],"tags":["nvd"],"epss":0.00235,"epssPercentile":0.14649,"ingestedAt":"2026-09-08T20:10:03.160Z","slug":"CVE-2026-77121","body":"## Overview\n\nA user account with permission to deploy artifacts to a hosted Maven repository could upload a POM file containing an oversized metadata field. This causes future attempts to list or browse that repository's components to permanently fail until an administrator repairs the underlying data. Only the targeted repository is affected; other repositories and overall server health remain unaffected.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}