Linuxsecurity
Fedora NextCloud Update Addresses JSON Tampering and DoS Vulnerabilities
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
On June 5, 2026, Fedora released updates for NextCloud addressing two critical vulnerabilities: CVE-2026-42044 and CVE-2026-44167. CVE-2026-42044 involves JSON response tampering via prototype pollution in Axios, while CVE-2026-44167 allows denial of service through untrusted ASN.1 file loading in phpseclib. Both vulnerabilities affect NextCloud versions prior to 33.0.4. Users are advised to upgrade to version 33.0.4 to mitigate these risks. The vulnerabilities were published on April 24 and May 12, 2026, respectively. The updates can be installed using the 'dnf' package manager. Immediate action is recommended to prevent potential exploitation.
Key Points: • Two critical vulnerabilities in NextCloud require immediate updates to version 33.0.4. • CVE-2026-42044 allows JSON response tampering via Axios, posing security risks. • CVE-2026-44167 enables denial of service through untrusted ASN.1 file loading.