MEDIUMCVSS 6.5Vulnerability
CVE-2026-77121
A user account with permission to deploy artifacts to a hosted Maven repository could upload a POM file containing an oversized metadata field. This causes future attempts to list or browse that repository's components to permanently fail until an administrator repairs the underlying data. Only the targeted repository is affected; other repositories and overall server health remain unaffected.
Properties
- severity
- MEDIUM
- epss_score
- 0.00397
- cvss_severity
- MEDIUM
- cvss_score
- 6.5
- retrieved_at
- 2026-09-30T10:42:41+00:00
- last_source
- FIRST EPSS
- score
- 6.5
- cve_id
- CVE-2026-77121
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- signal_observed_at
- 2026-09-30T10:33:35+00:00
- vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- published_at
- 2026-09-02T18:21:23.077
- last_modified
- 2026-09-29T19:18:18.977
- epss_percentile
- 0.3134
Related Entities (4)
ENRICHED_BY (1)
→[Source]FIRST EPSS
AFFECTS_PRODUCT (1)
→[Product]
DESCRIBED_BY (1)
→[Source]NVD
HAS_WEAKNESS (1)
→[Weakness]Allocation of Resources Without Limits or Throttling
Explore deeper with Ninja Signal's threat intelligence graph