CVE-2021-40143
Executive Summary
Sonatype Nexus Repository 3.x (≤3.33.1‑01) is vulnerable to HTTP header injection. An attacker can send a crafted request to inject arbitrary headers, enabling disclosure of sensitive data or forcing the server to request external resources. The flaw does not require authentication and can be exploited remotely. The vulnerability is not currently listed in the CISA KEV database.
Authoritative CVE Metadata - CVSS Base Score: 8.2 (HIGH) - Published: 2021-09-07T20:15:08.467 - Last Modified: 2026-09-22T18:12:20.300
Original Description: Sonatype Nexus Repository 3.x through 3.33.1-01 is vulnerable to an HTTP header injection. By sending a crafted HTTP request, a remote attacker may disclose sensitive information or request external resources from a vulnerable instance.
"This is the final test of a gentleman: his respect for those who can be of no possible value to him."
— William Lyon Phelps