Executive brief
JFrog Artifactory is a widely-used artifact repository manager that caches and distributes software packages across development teams. An unauthenticated attacker can trick the system into caching malicious or untrusted package content under specific conditions, compromising the integrity of cached artifacts and potentially disrupting service availability for teams relying on the repository.
Technical details
This vulnerability allows an unauthenticated attacker to inject untrusted or malicious package content into Artifactory's cache under specific conditions, exploiting insufficient validation or authentication checks in the caching mechanism. The attack is network-accessible and requires no user interaction or prior authentication. An attacker can poison the cache with malicious artifacts, leading to downstream developers unknowingly retrieving compromised packages, and can also exhaust cache resources to degrade service availability. Patches are available for affected versions 7.161.0 through 7.161.16; users should upgrade immediately.
Affected products
- JFrog Artifactory 7.161.0 to 7.161.16
Timeline
- 2026-08-12: disclosed
- 2026-08-13: advisory