FAIL › dossier
Sonatype
VENDOR· dossier confidence 20%
Sonatype is a software supply chain security vendor with a history of high-severity remote code execution vulnerabilities in its Nexus Repository Manager, requiring careful vendor risk assessment for defense-industrial-base customers.
PROFILE
Categorysoftware vendorWhat they doSonatype provides software supply chain security solutions, including vulnerability management and artifact repositories.
Websitehttps://www.sonatype.com ↗
SECURITY POSTURE
Sonatype has a mixed security posture, with a history of high-severity remote code execution vulnerabilities in its core Nexus Repository Manager product, though it has since improved its vulnerability disclosure and remediation processes.
Notable failures
- CVE-2019-7238 RCE in Nexus Repository Manager
- CVE-2020-10199 RCE in Nexus Repository
- CVE-2026-70329 unspecified vulnerability
Patterns: repeated high-severity RCE vulnerabilities in core repository management software; delayed patching of critical access control flaws
FAILURE HISTORY · 2
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2021-12-10 | CVE-2019-7238 | high | Sonatype Nexus Repository Manager before 3.15.0 has an incorrect access control vulnerability allowing remote code execution. |
| 2021-11-03 | CVE-2020-10199 | high | Sonatype Nexus Repository suffered a remote code execution vulnerability that was actively exploited in the wild. |
SENTIMENT · TRUSTED SOURCES
synthesissevere-fallout-0.60
Remote code execution in a widely used repository manager is a critical flaw with severe fallout, though the provided source is purely factual and lacks commentary on Sonatype's response or the broade
neutral
"Sonatype Nexus Repository contains an unspecified vulnerability that allows for remote code execution."
DOSSIER SOURCES
- Vulnerability Details REST API - Sonatype · help.sonatype.com
- Security Vulnerability Override API - Sonatype · help.sonatype.com
- Nvd - Cve-2026-70329 · NVD
Open questions: What is the exact patch timeline for CVE-2019-7238 and CVE-2020-10199? · How many customers were affected by these vulnerabilities?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-16 04:31:28.693179+00:00