Back Redpacketsecurity HackerOne Bug Bounty Disclosure: ssrf-via-user-controlled-push-proxyserver-in-notifications-push-registration
Report title SSRF via User-Controlled Push proxyServer in Notifications Push Registration
Report link
Date submitted 2026-09-30T15:43:58.441Z
A flaw in Nextcloud’s Notifications app allowed an authenticated user to set a custom server address when registering a push device. When a notification was sent, Nextcloud made a server-side request to that address. If local server requests were permitted in the Nextcloud configuration, this could be used to reach services running on the same server or its internal network.
The reporter also found that a test-notification endpoint returned information the attempted delivery. This could help a user check whether internal ports or services were reachable and, in some cases, see the response from the target. The risk therefore depended in part on the server’s configuration.
An attacker needed a valid Nextcloud account and had to be able to trigger a push notification for their account. The report does not show that the issue could be exploited against installations where Nextcloud’s protections block requests to local or internal addresses.
Nextcloud marked the report as resolved in its latest maintenance releases. Administrators should install the latest available updates and review their configuration for permissions that allow requests to local or internal servers.
A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.
If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.
HackerOne report summary
Programme
Profile
Report title SSRF via User-Controlled Push proxyServer in Notifications Push Registration
Report link
Date submitted 2026-09-30T15:43:58.441Z
A flaw in Nextcloud’s Notifications app allowed an authenticated user to set a custom server address when registering a push device. When a notification was sent, Nextcloud made a server-side request to that address. If local server requests were permitted in the Nextcloud configuration, this could be used to reach services running on the same server or its internal network.
The reporter also found that a test-notification endpoint returned information the attempted delivery. This could help a user check whether internal ports or services were reachable and, in some cases, see the response from the target. The risk therefore depended in part on the server’s configuration.
An attacker needed a valid Nextcloud account and had to be able to trigger a push notification for their account. The report does not show that the issue could be exploited against installations where Nextcloud’s protections block requests to local or internal addresses.
Nextcloud marked the report as resolved in its latest maintenance releases. Administrators should install the latest available updates and review their configuration for permissions that allow requests to local or internal servers.
A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.
If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
