---
id: CVE-2025-9868
title: >-
  Server-Side Request Forgery (SSRF) in the Remote Browser Plugin in Sonatype
  Nexus Repository 2.x up to and including 2.15.2 allows unauthenticated remote
  attackers to exfiltrate proxy repository credentials via crafted HTTP
  requests.
summary: >-
  Server-Side Request Forgery (SSRF) in the Remote Browser Plugin in Sonatype
  Nexus Repository 2.x up to and including 2.15.2 allows unauthenticated remote
  attackers to exfiltrate proxy repository credentials via crafted HTTP
  requests.
severity: none
cwe:
  - CWE-918
published: '2025-10-08'
updated: '2026-09-26'
sourceUpdated: '2026-09-26T00:10:00.127'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-9868'
references:
  - url: 'https://support.sonatype.com/hc/en-us/articles/45363201583635'
    label: 103e4ec9-0a87-450b-af77-479448ddef11
tags:
  - nvd
epss: 0.00495
epssPercentile: 0.39924
ingestedAt: '2026-09-26T00:22:39.960Z'
---

## Overview

Server-Side Request Forgery (SSRF) in the Remote Browser Plugin in Sonatype Nexus Repository 2.x up to and including 2.15.2 allows unauthenticated remote attackers to exfiltrate proxy repository credentials via crafted HTTP requests.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
