Linuxsecurity Fedora NextCloud Update Addresses JSON Tampering and DoS Vulnerabilities
Article Content
- •Two critical vulnerabilities in NextCloud require immediate updates to version 33.0.4.
- •CVE-2026-42044 allows JSON response tampering via Axios, posing security risks.
- •CVE-2026-44167 enables denial of service through untrusted ASN.1 file loading.
On June 5, 2026, Fedora released updates for NextCloud addressing two critical vulnerabilities: CVE-2026-42044 and CVE-2026-44167. CVE-2026-42044 involves JSON response tampering via prototype pollution in Axios, while CVE-2026-44167 allows denial of service through untrusted ASN.1 file loading in phpseclib. Both vulnerabilities affect NextCloud versions prior to 33.0.4. Users are advised to upgrade to version 33.0.4 to mitigate these risks. The vulnerabilities were published on April 24 and May 12, 2026, respectively. The updates can be installed using the 'dnf' package manager. Immediate action is recommended to prevent potential exploitation.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Fedora and CVE-2026-42044 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Multiple Vulnerabilities in Axios Affecting Ubuntu 26.04 LTS A series of vulnerabilities in Axios, a promise-based HTTP client, were discovered, affecting Ubuntu 26.04 LTS. Key issues include improper handling of NO_PROXY rules, which could allow attackers to bypass proxy restrictions and access internal services, leading to server-side request forgery (CVE-2025-62718…
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…