Skip to content
Fedora 43 Nextcloud Security Advisory XSS Security Bypass 2026

Fedora 43 Nextcloud Security Advisory XSS Security Bypass 2026

Linuxsecurity LinuxSecurity Advisories August 25, 2026

Find practical guidance for preventing, investigating, and responding to Linux security problems. Review Linux Privileges ×

NextCloud gives you universal access to your files through a web interface or

WebDAV. It also provides a platform to easily view & sync your contacts,

calendars and bookmarks across all your devices and enables basic editing right

on the web. NextCloud is extendable via a simple but powerful API for

applications and plugins.

* Sun Aug 16 2026 Andrew Bauer - 34.0.3-1 - 34.0.3 release RHBZ#2515297

* Sun Aug 16 2026 Andrew Bauer - 34.0.3-1 - 34.0.3 release RHBZ#2515297

[ 1 ] Bug #2506849 - CVE-2026-66010 nextcloud: DOMPurify: Cross-Site Scripting (XSS) via custom element attribute bypass [fedora-all] [ 2 ] Bug #2507002 - CVE-2026-65903 nextcloud: DOMPurify: Security bypass allows injection of malicious content [fedora-all] [ 3 ] Bug #2507015 - CVE-2026-65903 nextcloud: DOMPurify: Security bypass allows injection of malicious content [epel-all] [ 4 ] Bug #2508375 - CVE-2026-59883 nextcloud: Guzzle: Cross-host cookie disclosure and injection due to improper domain matching in CookieJar. [fedora-all] [ 5 ] Bug #2508377 - CVE-2026-59883 nextcloud: Guzzle: Cross-host cookie disclosure and injection due to improper domain matching in CookieJar. [epel-all]

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-625cbe86c8' at the command line. For more information, refer to the dnf documentation available at

Get the latest Linux and open source security news straight to your inbox.