BZ#2488275 CVE-2026-48998 nextcloud: guzzlehttp/psr7: Information disclosure via improper Host header validation [epel-all]
0
0
BZ#2488278 CVE-2026-48998 nextcloud: guzzlehttp/psr7: Information disclosure via improper Host header validation [fedora-all]
0
0
BZ#2489107 CVE-2026-49214 nextcloud: `guzzlehttp/psr7`: Request Smuggling and Cache Poisoning via HTTP Header Injection [epel-all]
0
0
BZ#2489108 CVE-2026-49214 nextcloud: `guzzlehttp/psr7`: Request Smuggling and Cache Poisoning via HTTP Header Injection [fedora-all]
0
0
BZ#2489147 CVE-2026-41148 nextcloud: Mermaid: CSS injection vulnerability allows page defacement and information disclosure [fedora-all]
0
0
BZ#2489154 CVE-2026-41148 nextcloud: Mermaid: CSS injection vulnerability allows page defacement and information disclosure [epel-all]
0
0
BZ#2489164 CVE-2026-54133 nextcloud: jmespath.php has CompilerRuntime code injection via unescaped function names [epel-all]
0
0
BZ#2489165 CVE-2026-54133 nextcloud: jmespath.php has CompilerRuntime code injection via unescaped function names [fedora-all]
0
0
BZ#2489259 CVE-2026-41149 nextcloud: Mermaid: HTML injection via classDef directive in state diagrams [epel-all]
0
0
BZ#2489262 CVE-2026-41149 nextcloud: Mermaid: HTML injection via classDef directive in state diagrams [fedora-all]
0
0
BZ#2491652 CVE-2026-42040 nextcloud: Axios: Incorrect null byte handling can lead to data integrity issues [epel-all]
0
0
BZ#2491660 CVE-2026-42040 nextcloud: Axios: Incorrect null byte handling can lead to data integrity issues [fedora-all]
0
0
BZ#2491781 CVE-2026-55766 nextcloud: guzzlehttp/psr7: Information disclosure due to improper handling of CR/LF characters in HTTP start-line fields [epel-all]
0
0
BZ#2491785 CVE-2026-55766 nextcloud: guzzlehttp/psr7: Information disclosure due to improper handling of CR/LF characters in HTTP start-line fields [fedora-all]
0
0
BZ#2491789 CVE-2026-55568 nextcloud: Guzzle: Information disclosure via cleartext proxy communication [fedora-all]
0
0
BZ#2491790 CVE-2026-55767 nextcloud: Guzzle: Cookie injection and session fixation due to improper domain validation [epel-all]
0
0
BZ#2491791 CVE-2026-55568 nextcloud: Guzzle: Information disclosure via cleartext proxy communication [epel-all]
0
0
BZ#2491792 CVE-2026-55767 nextcloud: Guzzle: Cookie injection and session fixation due to improper domain validation [fedora-all]
0
0
BZ#2492891 CVE-2026-42264 nextcloud: Axios: Prototype pollution allows information disclosure and request manipulation [epel-all]
0
0
BZ#2492905 CVE-2026-42264 nextcloud: Axios: Prototype pollution allows information disclosure and request manipulation [fedora-all]
This update has been submitted for testing by kni.
This update's test gating status has been changed to 'ignored'.
This update has been pushed to testing.
This update has been submitted for stable by bodhi.
This update has been pushed to stable.