See https://github.com/nextcloud/server/blob/master/SECURITY.md
Security: nextcloud/security-advisories
Security
SECURITY.md
-
Two-Factor Authentication Bypass via Pending Session Token ReplayGHSA-jgcj-v42r-9922 published
May 15, 2026 by DorraJaouadModerate -
Deleting a Forms collaborator share leaves uploaded response files accessible through a lingering Files shareGHSA-q4fw-6jf8-5vhh published
May 13, 2026 by DorraJaouadModerate -
Bypass of second factor authentication on DAV endpoints by reusing a pre-2FA session IDGHSA-mp6x-g55j-w9jw published
May 13, 2026 by DorraJaouadModerate -
Information Disclosure of view filter metadata via Broken Sensitive Data Masking in ViewServiceGHSA-vvxm-6jjp-m9mp published
May 13, 2026 by DorraJaouadModerate -
SQL Injection in Column Type Parameter Allows Arbitrary SQL ExecutionGHSA-x43f-gmgh-vvjj published
May 13, 2026 by DorraJaouadHigh -
Calendar app leaked user identifiers via attendee suggestion endpointGHSA-r697-74m9-gvf2 published
May 12, 2026 by DorraJaouadModerate -
Hidden Public Link creation when sharing to a Team External MemberGHSA-r3xh-x86g-hw4m published
May 12, 2026 by DorraJaouadModerate -
Files drop share links for end-to-end encrypted folders allowed to drop files into other folders of the share ownerGHSA-p3qw-7gwx-wg24 published
May 12, 2026 by DorraJaouadLow -
Valid share tokens allow to access tempory upload files of share ownerGHSA-45pj-p7x7-4mhc published
May 12, 2026 by DorraJaouadModerate -
Authentication Bypass in ID4me handling via Missing JWT Signature Verification in User OIDCGHSA-qqgv-fqwp-mjpp published
May 12, 2026 by DorraJaouadHigh
Learn more about advisories related to nextcloud/security-advisories in the GitHub Advisory Database