---
id: CVE-2026-77121
title: >-
  A user account with permission to deploy artifacts to a hosted Maven
  repository could upload a POM file containing an oversized metadata field
summary: >-
  A user account with permission to deploy artifacts to a hosted Maven
  repository could upload a POM file containing an oversized metadata field.
  This causes future attempts to list or browse that repository's components to
  permanently fai…
severity: none
cwe:
  - CWE-770
published: '2026-09-02'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T19:20:25.117'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-77121'
references:
  - url: >-
      https://help.sonatype.com/en/sonatype-nexus-repository-3-95-0-release-notes.html
    label: 103e4ec9-0a87-450b-af77-479448ddef11
  - url: 'https://support.sonatype.com/hc/en-us/articles/54635665756691/'
    label: 103e4ec9-0a87-450b-af77-479448ddef11
tags:
  - nvd
epss: 0.00235
epssPercentile: 0.14658
ingestedAt: '2026-09-08T20:10:03.160Z'
---

## Overview

A user account with permission to deploy artifacts to a hosted Maven repository could upload a POM file containing an oversized metadata field. This causes future attempts to list or browse that repository's components to permanently fail until an administrator repairs the underlying data. Only the targeted repository is affected; other repositories and overall server health remain unaffected.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
