Skip to content
Fedora NextCloud Update Addresses JSON Tampering and DoS Vulnerabilities

Fedora NextCloud Update Addresses JSON Tampering and DoS Vulnerabilities

First seen 5 Jun 2026, 12:10 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster June 6, 2026 at 11:53 UTC

On June 5, 2026, Fedora released updates for NextCloud addressing two critical vulnerabilities: CVE-2026-42044 and CVE-2026-44167. CVE-2026-42044 involves JSON response tampering via prototype pollution in Axios, while CVE-2026-44167 allows denial of service through untrusted ASN.1 file loading in phpseclib. Both vulnerabilities affect NextCloud versions prior to 33.0.4. Users are advised to upgrade to version 33.0.4 to mitigate these risks. The vulnerabilities were published on April 24 and May 12, 2026, respectively. The updates can be installed using the 'dnf' package manager. Immediate action is recommended to prevent potential exploitation.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 97d ago How this analysis works

Timeline

2026-04-24
CVE-2026-42044 published
NextCloud vulnerability discovered allowing JSON response tampering via Axios.
Linuxsecurity
2026-05-12
CVE-2026-44167 published
NextCloud vulnerability identified enabling denial of service through ASN.1 file loading.
Linuxsecurity
2026-06-05
Fedora releases updates for NextCloud
Fedora advises users to upgrade to NextCloud version 33.0.4 to address critical vulnerabilities.
Linuxsecurity

More articles in this cluster (2)

Following this threat?

Track Fedora and CVE-2026-42044 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed