stable

nextcloud-33.0.6-1.fc43

FEDORA-2026-5afe6630dc created by kni a month ago for Fedora 43

33.0.6 Release

How to install

Updates may require up to 24 hours to propagate to mirrors. If the following command doesn't work, please retry later:

sudo dnf upgrade --refresh --advisory=FEDORA-2026-5afe6630dc

This update has been submitted for testing by kni.

a month ago

This update's test gating status has been changed to 'ignored'.

a month ago

This update has been pushed to testing.

a month ago

This update has been submitted for stable by bodhi.

a month ago

This update has been pushed to stable.

a month ago

Please log in to add feedback.

Metadata
Type
security
Severity
high
Karma
0
Signed
Content Type
RPM
Test Gating
Autopush Settings
Unstable by Karma
-3
Stable by Karma
3
Stable by Time
7 days
Dates
submitted
a month ago
in testing
a month ago
in stable
a month ago
approved
a month ago
BZ#2486357 nextcloud-34.0.1 is available
0
0
BZ#2486491 CVE-2026-41150 nextcloud: Mermaid: Denial of Service via specially crafted gantt charts [epel-all]
0
0
BZ#2486496 CVE-2026-41150 nextcloud: Mermaid: Denial of Service via specially crafted gantt charts [fedora-all]
0
0
BZ#2487344 .map file update is fragile
0
0
BZ#2487477 CVE-2026-8723 nextcloud: qs: Denial of Service due to improper handling of null/undefined array elements [epel-all]
0
0
BZ#2487498 CVE-2026-8723 nextcloud: qs: Denial of Service due to improper handling of null/undefined array elements [fedora-all]
0
0
BZ#2488103 CVE-2026-44495 nextcloud: Axios: Information disclosure due to prototype pollution vulnerability [fedora-all]
0
0
BZ#2488116 CVE-2026-44489 nextcloud: Axios: Information disclosure via Prototype Pollution [fedora-all]
0
0
BZ#2488118 CVE-2026-44495 nextcloud: Axios: Information disclosure due to prototype pollution vulnerability [epel-all]
0
0
BZ#2488119 CVE-2026-44489 nextcloud: Axios: Information disclosure via Prototype Pollution [epel-all]
0
0
BZ#2488129 CVE-2026-44490 nextcloud: Axios: Information disclosure and denial of service due to prototype pollution [fedora-all]
0
0
BZ#2488137 CVE-2026-44490 nextcloud: Axios: Information disclosure and denial of service due to prototype pollution [epel-all]
0
0
BZ#2488146 CVE-2026-44488 nextcloud: Axios: Denial of Service due to unenforced request and response size limits [epel-all]
0
0
BZ#2488154 CVE-2026-44488 nextcloud: Axios: Denial of Service due to unenforced request and response size limits [fedora-all]
0
0
BZ#2488159 CVE-2026-44487 nextcloud: Axios: Information disclosure of proxy credentials via redirect flows [epel-all]
0
0
BZ#2488171 CVE-2026-44487 nextcloud: Axios: Information disclosure of proxy credentials via redirect flows [fedora-all]
0
0
BZ#2488186 CVE-2026-44494 nextcloud: Axios: Man-in-the-Middle (MITM) attack via Prototype Pollution [epel-all]
0
0
BZ#2488188 CVE-2026-44494 nextcloud: Axios: Man-in-the-Middle (MITM) attack via Prototype Pollution [fedora-all]
0
0
BZ#2488192 CVE-2026-44486 nextcloud: Axios: Information disclosure of proxy credentials via HTTP redirects [epel-all]
0
0
BZ#2488196 CVE-2026-44486 nextcloud: Axios: Information disclosure of proxy credentials via HTTP redirects [fedora-all]
0
0
BZ#2488202 CVE-2026-44496 nextcloud: Axios: Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name [epel-all]
0
0
BZ#2488207 CVE-2026-44496 nextcloud: Axios: Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name [fedora-all]
0
0
BZ#2488219 CVE-2026-44492 nextcloud: Axios: Proxy bypass via IPv4-mapped IPv6 address non-normalization [fedora-all]
0
0
BZ#2488224 CVE-2026-44492 nextcloud: Axios: Proxy bypass via IPv4-mapped IPv6 address non-normalization [epel-all]
0
0
BZ#2488275 CVE-2026-48998 nextcloud: guzzlehttp/psr7: Information disclosure via improper Host header validation [epel-all]
0
0
BZ#2488278 CVE-2026-48998 nextcloud: guzzlehttp/psr7: Information disclosure via improper Host header validation [fedora-all]
0
0
BZ#2489107 CVE-2026-49214 nextcloud: `guzzlehttp/psr7`: Request Smuggling and Cache Poisoning via HTTP Header Injection [epel-all]
0
0
BZ#2489108 CVE-2026-49214 nextcloud: `guzzlehttp/psr7`: Request Smuggling and Cache Poisoning via HTTP Header Injection [fedora-all]
0
0
BZ#2489147 CVE-2026-41148 nextcloud: Mermaid: CSS injection vulnerability allows page defacement and information disclosure [fedora-all]
0
0
BZ#2489154 CVE-2026-41148 nextcloud: Mermaid: CSS injection vulnerability allows page defacement and information disclosure [epel-all]
0
0
BZ#2489164 CVE-2026-54133 nextcloud: jmespath.php has CompilerRuntime code injection via unescaped function names [epel-all]
0
0
BZ#2489165 CVE-2026-54133 nextcloud: jmespath.php has CompilerRuntime code injection via unescaped function names [fedora-all]
0
0
BZ#2489259 CVE-2026-41149 nextcloud: Mermaid: HTML injection via classDef directive in state diagrams [epel-all]
0
0
BZ#2489262 CVE-2026-41149 nextcloud: Mermaid: HTML injection via classDef directive in state diagrams [fedora-all]
0
0
BZ#2491652 CVE-2026-42040 nextcloud: Axios: Incorrect null byte handling can lead to data integrity issues [epel-all]
0
0
BZ#2491660 CVE-2026-42040 nextcloud: Axios: Incorrect null byte handling can lead to data integrity issues [fedora-all]
0
0
BZ#2491781 CVE-2026-55766 nextcloud: guzzlehttp/psr7: Information disclosure due to improper handling of CR/LF characters in HTTP start-line fields [epel-all]
0
0
BZ#2491785 CVE-2026-55766 nextcloud: guzzlehttp/psr7: Information disclosure due to improper handling of CR/LF characters in HTTP start-line fields [fedora-all]
0
0
BZ#2491789 CVE-2026-55568 nextcloud: Guzzle: Information disclosure via cleartext proxy communication [fedora-all]
0
0
BZ#2491790 CVE-2026-55767 nextcloud: Guzzle: Cookie injection and session fixation due to improper domain validation [epel-all]
0
0
BZ#2491791 CVE-2026-55568 nextcloud: Guzzle: Information disclosure via cleartext proxy communication [epel-all]
0
0
BZ#2491792 CVE-2026-55767 nextcloud: Guzzle: Cookie injection and session fixation due to improper domain validation [fedora-all]
0
0
BZ#2492891 CVE-2026-42264 nextcloud: Axios: Prototype pollution allows information disclosure and request manipulation [epel-all]
0
0
BZ#2492905 CVE-2026-42264 nextcloud: Axios: Prototype pollution allows information disclosure and request manipulation [fedora-all]
0
0

Automated Test Results