Skip to content
SSRF Vulnerability Disclosed in Nextcloud Notifications App

SSRF Vulnerability Disclosed in Nextcloud Notifications App

First seen 1 Oct 2026, 20:05 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 1, 2026 at 21:05 UTC
  • •Nextcloud's Notifications app has an SSRF vulnerability affecting authenticated users.
  • •Exploitation requires specific server settings to be enabled.
  • •Nextcloud has issued a fix, and users are urged to update immediately.

A server-side request forgery (SSRF) vulnerability was disclosed in Nextcloud’s Notifications app, allowing authenticated users to set a push-notification proxy address of their choice. This could enable users to make requests to internal services when notifications are sent. The vulnerability was demonstrated by a normal user and requires the 'allow_local_remote_servers' setting to be enabled for exploitation. Nextcloud has resolved the issue in its latest maintenance releases, and users are advised to update their systems and review their configurations. The researcher who reported the bug received a $150 bounty for their findings. The report was submitted on September 30, 2026.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-30
Vulnerability report submitted
A researcher reported an SSRF vulnerability in Nextcloud’s Notifications app, allowing user-controlled proxy settings.
Redpacketsecurity
Recent
Nextcloud resolves the issue
Nextcloud marked the SSRF vulnerability as resolved in its latest maintenance releases, urging users to update.
Redpacketsecurity

More articles in this cluster (2)

Common questions

What versions of Nextcloud are affected?
The article does not specify exact versions, but it mentions the Notifications app is vulnerable.
Is this vulnerability actively being exploited?
No active exploitation has been reported; the vulnerability was disclosed and patched.
What should users do to protect their systems?
Users should update to the latest version of Nextcloud and review their server settings regarding local remote servers.