Back Linuxsecurity Fedora 43 nextcloud 33.0.4 Critical JSON Tampering DoS CVE-2026
[ 1 ] Bug #2467998 - CVE-2026-42044 nextcloud: Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget [epel-all] [ 2 ] Bug #2468008 - CVE-2026-42044 nextcloud: Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget [fedora-all] [ 3 ] Bug #2476733 - CVE-2026-44167 nextcloud: phpseclib: Denial of Service via untrusted ASN.1 file loading [fedora-all] [ 4 ] Bug #2476734 - CVE-2026-44167 nextcloud: phpseclib: Denial of Service via untrusted ASN.1 file loading [epel-all] [ 5 ] Bug #2482794 - nextcloud-33.0.4 is available
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-e187104307' at the command line. For more information, refer to the dnf documentation available at
Get the latest Linux and open source security news straight to your inbox.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
