Skip to content
Fedora 45 Nextcloud 34.0.4 Denial of Service and XSS Issues 2026

Fedora 45 Nextcloud 34.0.4 Denial of Service and XSS Issues 2026

Linuxsecurity •LinuxSecurity Advisories • September 28, 2026

CISA confirms exploitation of a Linux firewall flaw. Check if your systems need the fix. ×

NextCloud gives you universal access to your files through a web interface or

WebDAV. It also provides a platform to easily view & sync your contacts,

calendars and bookmarks across all your devices and enables basic editing right

on the web. NextCloud is extendable via a simple but powerful API for

applications and plugins.

* Sat Sep 19 2026 Andrew Bauer - 34.0.4-1 - 34.0.4 Release

* Sat Sep 19 2026 Andrew Bauer - 34.0.4-1 - 34.0.4 Release

[ 1 ] Bug #2526255 - CVE-2026-48988 nextcloud: markdown-it: Denial of Service via quadratic processing of smartquotes with typographer enabled [epel-all] [ 2 ] Bug #2526261 - CVE-2026-48988 nextcloud: markdown-it: Denial of Service via quadratic processing of smartquotes with typographer enabled [fedora-all] [ 3 ] Bug #2527333 - CVE-2026-82562 nextcloud: qs: Denial of Service via array limit bypass in query string parsing [fedora-all] [ 4 ] Bug #2527355 - CVE-2026-82562 nextcloud: qs: Denial of Service via array limit bypass in query string parsing [epel-all] [ 5 ] Bug #2527907 - CVE-2026-82417 nextcloud: qs: Denial of Service via improper validation in stringify function [epel-all]

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-5c1bbb46c3' at the command line. For more information, refer to the dnf documentation available at

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Linux Security - Your source for Top Linux News, Advisories, HOWTOs and Feature Releases

Extracted Entities

Attack Types (1)

Platforms (3)

Vulnerabilities (1)