Fedora NextCloud Update Addresses JSON Tampering and DoS Vulnerabilities

Fedora NextCloud Update Addresses JSON Tampering and DoS Vulnerabilities

First seen 5 Jun 2026, 12:10 UTC Linuxsecurity 97% similarity 72.0

Article Content

Browse articles
ThreatCluster

On June 5, 2026, Fedora released updates for NextCloud addressing two critical vulnerabilities: CVE-2026-42044 and CVE-2026-44167. CVE-2026-42044 involves JSON response tampering via prototype pollution in Axios, while CVE-2026-44167 allows denial of service through untrusted ASN.1 file loading in phpseclib. Both vulnerabilities affect NextCloud versions prior to 33.0.4. Users are advised to upgrade to version 33.0.4 to mitigate these risks. The vulnerabilities were published on April 24 and May 12, 2026, respectively. The updates can be installed using the 'dnf' package manager. Immediate action is recommended to prevent potential exploitation.

Key Points: • Two critical vulnerabilities in NextCloud require immediate updates to version 33.0.4. • CVE-2026-42044 allows JSON response tampering via Axios, posing security risks. • CVE-2026-44167 enables denial of service through untrusted ASN.1 file loading.

ThreatCluster AI

Timeline

2026-04-24
CVE-2026-42044 published
NextCloud vulnerability discovered allowing JSON response tampering via Axios.
Linuxsecurity
2026-05-12
CVE-2026-44167 published
NextCloud vulnerability identified enabling denial of service through ASN.1 file loading.
Linuxsecurity
2026-06-05
Fedora releases updates for NextCloud
Fedora advises users to upgrade to NextCloud version 33.0.4 to address critical vulnerabilities.
Linuxsecurity

Community

Browse all →

Tracked Entities in This Story