MEDIUMCVSS 6.5Vulnerability

CVE-2026-77121

A user account with permission to deploy artifacts to a hosted Maven repository could upload a POM file containing an oversized metadata field. This causes future attempts to list or browse that repository's components to permanently fail until an administrator repairs the underlying data. Only the targeted repository is affected; other repositories and overall server health remain unaffected.

Properties

severity
MEDIUM
epss_score
0.00397
cvss_severity
MEDIUM
cvss_score
6.5
retrieved_at
2026-09-30T10:42:41+00:00
last_source
FIRST EPSS
score
6.5
cve_id
CVE-2026-77121
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
signal_observed_at
2026-09-30T10:33:35+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
published_at
2026-09-02T18:21:23.077
last_modified
2026-09-29T19:18:18.977
epss_percentile
0.3134

Related Entities (4)

ENRICHED_BY (1)

→[Source]FIRST EPSS

AFFECTS_PRODUCT (1)

→[Product]

DESCRIBED_BY (1)

→[Source]NVD

HAS_WEAKNESS (1)

→[Weakness]Allocation of Resources Without Limits or Throttling

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-77121 (CVSS 6.5) — Ninja Signal Threat Intelligence | Ninja Signal