AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2025-9868

UNKNOWN · CVSS N/A EPSS 0.46%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2025-10-08 · Last synced 2026-08-04

CyberRota Analysis

This vulnerability has an unknown severity rating. It may be remotely exploitable.

CVE
CVE-2025-9868
Severity
UNKNOWN
CVSS
N/A
EPSS
0.46%

Original NVD Description

Server-Side Request Forgery (SSRF) in the Remote Browser Plugin in Sonatype Nexus Repository 2.x up to and including 2.15.2 allows unauthenticated remote attackers to exfiltrate proxy repository credentials via crafted HTTP requests.