Skip to content
HackerOne Bug Bounty Disclosure: ssrf-via-user-controlled-push-proxyserver-in-notifications-push-registration

HackerOne Bug Bounty Disclosure: ssrf-via-user-controlled-push-proxyserver-in-notifications-push-registration

Redpacketsecurity •admin • October 1, 2026

Report title SSRF via User-Controlled Push proxyServer in Notifications Push Registration

Report link

Date submitted 2026-09-30T15:43:58.441Z

A vulnerability in Nextcloud’s Notifications app allowed an authenticated user to set a push-notification proxy address of their choice. When a notification was sent, the server made an HTTP request to that address. This could let a user make the Nextcloud server other systems, including internal services—a type of vulnerability known as server-side request forgery (SSRF).

Why could this matter?

The report also showed that a user could receive details the server’s request and the target service’s response through a Notifications API endpoint. This could help probe internal services. The researcher noted that their test required Nextcloud’s allow_local_remote_servers setting to be enabled, so the impact depends in part on that configuration.

Who could exploit it?

The issue was demonstrated by a normal, authenticated user. Exploitation also depended on a notification being sent to the user whose push settings had been changed.

Nextcloud marked the report as resolved in its latest maintenance releases. Users should update to a fixed version and review whether their server needs to allow requests to local or private network addresses.

Nextcloud triaged and resolved the report, then awarded the researcher a $150 bounty.

A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.

If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.

HackerOne report summary

Programme

Profile

Report title SSRF via User-Controlled Push proxyServer in Notifications Push Registration

Report link

Date submitted 2026-09-30T15:43:58.441Z

A vulnerability in Nextcloud’s Notifications app allowed an authenticated user to set a push-notification proxy address of their choice. When a notification was sent, the server made an HTTP request to that address. This could let a user make the Nextcloud server other systems, including internal services—a type of vulnerability known as server-side request forgery (SSRF).

Why could this matter?

The report also showed that a user could receive details the server’s request and the target service’s response through a Notifications API endpoint. This could help probe internal services. The researcher noted that their test required Nextcloud’s allow_local_remote_servers setting to be enabled, so the impact depends in part on that configuration.

Who could exploit it?

The issue was demonstrated by a normal, authenticated user. Exploitation also depended on a notification being sent to the user whose push settings had been changed.

Nextcloud marked the report as resolved in its latest maintenance releases. Users should update to a fixed version and review whether their server needs to allow requests to local or private network addresses.

Nextcloud triaged and resolved the report, then awarded the researcher a $150 bounty.

A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.

If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.

Extracted Entities