nextcloud-server-34

Direct Vulnerabilities

Known vulnerabilities in the nextcloud-server-34 package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • L
GHSA-hrr3-gc8f-f4qj

<34.0.4-r6
  • L
CVE-2026-86472

<34.0.4-r6
  • L
Resource Exhaustion

<34.0.4-r4
  • L
GHSA-q2hr-2g5m-vwhr

<34.0.4-r4
  • L
GHSA-jxrp-r7gx-q4j8

<34.0.3-r1
  • M
Cross-site Scripting (XSS)

<34.0.3-r1
  • L
GHSA-6j4f-fj2g-mc7p

<34.0.4-r3
  • L
GHSA-qw65-cvwx-89v3

<34.0.4-r3
  • L
GHSA-qhr7-859c-m2p7

<34.0.4-r3
  • L
CVE-2026-84394

<34.0.4-r3
  • L
GHSA-58mr-gqgx-xq4g

<34.0.4-r3
  • L
Resource Exhaustion

<34.0.4-r3
  • L
CVE-2026-84292

<34.0.4-r3
  • L
Resource Exhaustion

<34.0.4-r3
  • L
GHSA-542g-h47m-68v8

<34.0.4-r2
  • L
Arbitrary Code Injection

<34.0.4-r2
  • L
GHSA-r4gj-5m52-g5wh

<34.0.4-r2
  • L
Resource Exhaustion

<34.0.4-r2
  • L
GHSA-vh66-26gq-q6x8

<34.0.4-r2
  • L
GHSA-c29m-xwm3-cm6r

<34.0.4-r2
  • L
GHSA-j8rh-479h-cp32

<34.0.4-r2
  • L
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<34.0.4-r2
  • L
Resource Exhaustion

<34.0.4-r2
  • L
Server-Side Request Forgery (SSRF)

<34.0.4-r2
  • L
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<34.0.4-r2
  • L
GHSA-4hqw-qxg8-jxx2

<34.0.4-r2
  • L
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<34.0.4-r2
  • L
Arbitrary Code Injection

<34.0.4-r2
  • L
GHSA-x97p-jq2g-jp4f

<34.0.4-r2
  • L
CVE-2026-101899

<34.0.4-r2
  • L
GHSA-mghh-pgcx-3jjj

<34.0.4-r2
  • L
GHSA-3pq3-5fj3-cg6v

<34.0.4-r2
  • L
Unintended Proxy or Intermediary ('Confused Deputy')

<34.0.4-r2
  • L
GHSA-9fr6-4gfg-395g

<34.0.4-r2
  • L
Inefficient Regular Expression Complexity

<34.0.4-r2
  • L
Unintended Proxy or Intermediary ('Confused Deputy')

<34.0.4-r2
  • L
GHSA-44g4-m2mj-wpvx

<34.0.4-r2
  • L
GHSA-m8m8-qj5v-23w3

<34.0.4-r2
  • L
GHSA-4p3w-j4w9-5jqw

<34.0.4-r1
  • L
CVE-2026-17495

<34.0.4-r1
  • L
GHSA-3mcp-22mf-vrw3

<34.0.2-r4
  • H
Uncontrolled Recursion

<34.0.2-r4
  • L
GHSA-73wf-gq98-2v4g

<34.0.3-r4
  • L
Uncaught Exception

<34.0.3-r4
  • L
Allocation of Resources Without Limits or Throttling

<34.0.3-r4
  • L
GHSA-c83g-rgw3-j3cx

<34.0.3-r4
  • L
GHSA-f65p-4m7j-42xc

<34.0.3-r3
  • L
CVE-2026-75899

<34.0.3-r3
  • L
GHSA-5jgf-p345-68v8

<34.0.3-r3
  • L
GHSA-fph4-wmhf-6fwf

<34.0.3-r3
  • L
CVE-2026-76172

<34.0.3-r3
  • L
CVE-2026-75975

<34.0.3-r3
  • L
GHSA-jqff-g426-hqxp

<34.0.3-r3
  • L
CVE-2026-75931

<34.0.3-r3
  • L
GHSA-39j5-w47m-2gmv

<34.0.2-r4
  • H
Allocation of Resources Without Limits or Throttling

<34.0.2-r4
  • H
Resource Exhaustion

<34.0.2-r4
  • L
GHSA-fqj3-h9pc-443h

<34.0.2-r4
  • M
Resource Exhaustion

<34.0.2-r4
  • L
GHSA-fq2j-3j99-rx65

<34.0.2-r4
  • H
Information Exposure

<34.0.2-r4
  • L
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<34.0.2-r4
  • L
GHSA-9wx3-p993-35vp

<34.0.2-r4
  • L
GHSA-68jp-44vc-2x5h

<34.0.2-r4
  • L
GHSA-6hqm-hm2v-3p2p

<34.0.2-r4
  • H
Permissive Whitelist

<34.0.2-r4
  • L
GHSA-vcc3-ghjq-m6fr

<34.0.3-r2
  • L
CVE-2026-45822

<34.0.3-r2
  • H
Resource Exhaustion

<34.0.2-r4
  • H
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<34.0.2-r4
  • L
GHSA-f2r5-pqh9-r8f8

<34.0.2-r4
  • L
GHSA-4ww2-rjh2-xpv9

<34.0.2-r4
  • L
GHSA-pcw8-m77r-2528

<34.0.2-r0
  • L
Directory Traversal

<34.0.2-r2
  • L
GHSA-55q2-fjhq-7xh7

<34.0.3-r1
  • L
GHSA-c2j3-45gr-mqc4

<34.0.3-r1
  • L
GHSA-38gx-cfqf-f652

<34.0.2-r4
  • M
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<34.0.2-r4
  • L
Integer Overflow or Wraparound

<34.0.2-r7
  • M
Directory Traversal

<34.0.2-r7
  • L
GHSA-fxqj-rqcc-2cmp

<34.0.2-r7
  • L
GHSA-v56q-mh7h-f735

<34.0.2-r7
  • L
GHSA-xvcm-6775-5m9r

<34.0.2-r7
  • L
Algorithmic Complexity

<34.0.2-r7
  • L
CVE-2026-18446

<34.0.2-r5
  • L
GHSA-7p8r-x3mc-p8w7

<34.0.2-r5
  • L
Resource Exhaustion

<34.0.2-r6
  • L
GHSA-4c8g-83qw-93j6

<34.0.2-r5
  • L
GHSA-rgw5-rvv9-x895

<34.0.2-r6
  • L
GHSA-v2hh-gcrm-f6hx

<34.0.2-r5
  • L
CVE-2026-13676

<34.0.2-r5
  • L
CVE-2026-16221

<34.0.2-r5
  • L
GHSA-gcfj-64vw-6mp9

<34.0.2-r4
  • L
GHSA-jqh4-m9w3-8hp9

<34.0.2-r4
  • M
Allocation of Resources Without Limits or Throttling

<34.0.1-r9
  • L
GHSA-mwf2-3pr3-8698

<34.0.2-r4
  • M
Information Exposure

<34.0.1-r9
  • L
GHSA-pmv8-rq9r-6j72

<34.0.2-r4
  • L
GHSA-32rq-jhr7-m3hh

<34.0.1-r9
  • L
GHSA-42h9-826w-cgv3

<34.0.2-r4
  • L
GHSA-7q8q-rj6j-mhjq

<34.0.2-r4
  • L
GHSA-mmx7-hfxf-jppx

<34.0.2-r4
  • M
Information Exposure

<34.0.1-r9
  • L
GHSA-3fvr-2jw6-crq4

<34.0.1-r9
  • L
GHSA-hcpx-6fm6-wx23

<34.0.2-r4
  • L
GHSA-mjrx-74jh-7xgw

<34.0.1-r9
  • L
GHSA-mqq9-gxg5-m58g

<34.0.1-r9
  • M
Information Exposure

<34.0.1-r9
  • L
GHSA-xj6q-8x83-jv6g

<34.0.2-r4
  • L
GHSA-f4gw-2p7v-4548

<34.0.2-r4
  • L
CVE-2026-14257

<34.0.2-r3
  • L
GHSA-mh99-v99m-4gvg

<34.0.2-r3
  • C
Directory Traversal

<34.0.2-r2
  • L
GHSA-r28c-9q8g-f849

<34.0.2-r2
  • L
GHSA-6g55-p6wh-862q

<34.0.2-r2
  • L
GHSA-3jxr-9vmj-r5cp

<34.0.2-r1
  • L
CVE-2026-13149

<34.0.2-r1
  • H
Cross-site Scripting (XSS)

<34.0.1-r4
  • M
Cross-site Scripting (XSS)

<34.0.1-r4
  • M
Trust Boundary Violation

<34.0.1-r4
  • M
Protection Mechanism Failure

<34.0.1-r4
  • M
Cross-site Scripting (XSS)

<34.0.1-r4
  • L
Improper Input Validation

<34.0.2-r0
  • L
GHSA-fx2h-pf6j-xcff

<34.0.1-r9
  • L
GHSA-94pj-82f3-465w

<34.0.1-r9
  • L
GHSA-v6wh-96g9-6wx3

<34.0.1-r9
  • L
GHSA-wm3w-8rrp-j577

<34.0.1-r9
  • L
GHSA-f283-ghqc-fg79

<34.0.1-r9
  • L
Directory Traversal

<34.0.1-r9
  • L
External Control of File Name or Path

<34.0.1-r9
  • L
GHSA-h95v-h523-3mw8

<34.0.1-r9
  • L
GHSA-w5hq-g745-h8pq

<34.0.1-r7
  • H
Out-of-bounds Write

<34.0.1-r7
  • L
GHSA-qx2v-qp2m-jg93

<34.0.1-r6
  • L
Cross-site Scripting (XSS)

<34.0.1-r6
  • H
Resource Exhaustion

<34.0.1-r5
  • L
GHSA-f886-m6hf-6m8v

<34.0.1-r5
  • M
Cross-site Scripting (XSS)

<34.0.1-r4
  • L
GHSA-r47g-fvhr-h676

<34.0.1-r4
  • L
GHSA-cmwh-pvxp-8882

<34.0.1-r4
  • L
GHSA-x4vx-rjvf-j5p4

<34.0.1-r4
  • L
Cross-site Scripting (XSS)

<34.0.1-r4
  • L
GHSA-vxr8-fq34-vvx9

<34.0.1-r4
  • L
GHSA-hpcv-96wg-7vj8

<34.0.1-r4
  • L
GHSA-76mc-f452-cxcm

<34.0.1-r4
  • L
Cross-site Scripting (XSS)

<34.0.1-r4
  • L
GHSA-gvmj-g25r-r7wr

<34.0.1-r4
  • L
GHSA-rp9w-3fw7-7cwq

<34.0.1-r4
  • L
GHSA-34xg-wgjx-8xph

<34.0.1-r3
  • L
GHSA-cwxw-98qj-8qjx

<34.0.1-r3
  • L
Origin Validation Error

<34.0.1-r3
  • L
CRLF Injection

<34.0.1-r3
  • L
Missing Encryption of Sensitive Data

<34.0.1-r3
  • L
GHSA-wpwq-4j6v-78m3

<34.0.1-r3
  • L
Improper Input Validation

<34.0.1-r3
  • L
Improper Input Validation

<34.0.1-r3
  • L
GHSA-hq7v-mx3g-29hw

<34.0.1-r3
  • L
GHSA-vm85-hxw5-5432

<34.0.1-r3
  • L
GHSA-hmw2-7cc7-3qxx

<34.0.1-r2
  • L
CVE-2026-12143

<34.0.1-r2
  • L
Information Exposure

<34.0.1-r1
  • L
GHSA-62hf-57xw-28j9

<34.0.1-r1
  • L
GHSA-35jp-ww65-95wh

<34.0.1-r1
  • M
Improper Authentication

<34.0.1-r1
  • L
Improper Encoding or Escaping of Output

<34.0.1-r1
  • L
GHSA-pjwm-pj3p-43mv

<34.0.1-r1
  • L
GHSA-xx6v-rp6x-q39c

<34.0.1-r1
  • L
GHSA-xhjh-pmcv-23jw

<34.0.1-r1
  • L
Permissive Whitelist

<34.0.1-r1
  • L
GHSA-m7pr-hjqh-92cm

<34.0.1-r1
  • L
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<34.0.1-r1
  • L
GHSA-3w6x-2g7m-8v23

<34.0.1-r1
  • L
GHSA-q8qp-cvcw-x6jj

<34.0.1-r1
  • L
GHSA-898c-q2cr-xwhg

<34.0.1-r1
  • L
Server-Side Request Forgery (SSRF)

<34.0.1-r1
  • L
GHSA-pf86-5x62-jrwf

<34.0.1-r1
  • L
Allocation of Resources Without Limits or Throttling

<34.0.1-r1
  • L
GHSA-6chq-wfr3-2hj9

<34.0.1-r1
  • L
GHSA-3g43-6gmg-66jw

<34.0.1-r1
  • C
Permissive Whitelist

<34.0.1-r1
  • C
Improperly Controlled Modification of Dynamically-Determined Object Attributes

<34.0.1-r1
  • H
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<34.0.1-r1
  • L
GHSA-445q-vr5w-6q77

<34.0.1-r1
  • L
HTTP Response Splitting

<34.0.1-r1
  • H
Arbitrary Code Injection

<34.0.1-r1
  • H
Uncontrolled Recursion

<34.0.1-r1
  • H
Server-Side Request Forgery (SSRF)

<34.0.1-r1
  • L
CRLF Injection

<34.0.1-r1
  • L
GHSA-777c-7fjr-54vf

<34.0.1-r1
  • L
GHSA-w9j2-pvgh-6h63

<34.0.1-r1
  • L
GHSA-p92q-9vqr-4j8v

<34.0.1-r1
  • L
Allocation of Resources Without Limits or Throttling

<34.0.1-r1
  • L
GHSA-5c9x-8gcm-mpgx

<34.0.1-r1
  • C
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<34.0.1-r1
  • L
GHSA-j5f8-grm9-p9fc

<34.0.1-r1
  • L
Resource Exhaustion

<34.0.1-r1
  • L
Allocation of Resources Without Limits or Throttling

<34.0.1-r1
  • L
Unintended Proxy or Intermediary ('Confused Deputy')

<34.0.1-r1
  • L
GHSA-hfxv-24rg-xrqf

<34.0.1-r1
  • L
GHSA-pmwg-cvhr-8vh7

<34.0.1-r1
  • L
GHSA-vf2m-468p-8v99

<34.0.1-r1
  • H
Information Exposure

<34.0.1-r1
  • L
GHSA-38cx-cq6f-5755

<34.0.1-r0
  • L
Incomplete Blacklist

<34.0.1-r0