nextcloud-server-31

Direct Vulnerabilities

Known vulnerabilities in the nextcloud-server-31 package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • L
GHSA-2v37-7h3g-55p8

<31.0.14-r7
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<31.0.14-r7
  • L
Directory Traversal

<31.0.14-r6
  • L
GHSA-6g55-p6wh-862q

<31.0.14-r6
  • L
GHSA-r28c-9q8g-f849

<31.0.14-r6
  • C
Directory Traversal

<31.0.14-r6
  • L
CVE-2026-14257

<31.0.14-r6
  • L
Resource Exhaustion

<31.0.14-r6
  • L
GHSA-f7vp-7xgx-4w4r

<31.0.14-r6
  • L
Incorrect Behavior Order: Validate Before Canonicalize

<31.0.14-r6
  • L
Incorrect Behavior Order: Validate Before Canonicalize

<31.0.14-r6
  • L
GHSA-v5mv-p594-2x33

<31.0.14-r6
  • L
GHSA-rgw5-rvv9-x895

<31.0.14-r6
  • L
GHSA-mh99-v99m-4gvg

<31.0.14-r6
  • L
Cross-site Scripting (XSS)

<31.0.14-r6
  • L
GHSA-fxqj-rqcc-2cmp

<31.0.14-r6
  • L
GHSA-qx2v-qp2m-jg93

<31.0.14-r6
  • M
Directory Traversal

<31.0.14-r6
  • L
GHSA-mqq9-gxg5-m58g

<31.0.14-r5
  • M
Information Exposure

<31.0.14-r5
  • M
Information Exposure

<31.0.14-r5
  • L
GHSA-32rq-jhr7-m3hh

<31.0.14-r5
  • M
Information Exposure

<31.0.14-r5
  • L
GHSA-3fvr-2jw6-crq4

<31.0.14-r5
  • M
Allocation of Resources Without Limits or Throttling

<31.0.14-r5
  • L
GHSA-mjrx-74jh-7xgw

<31.0.14-r5
  • L
CRLF Injection

<31.0.14-r5
  • L
GHSA-wm3w-8rrp-j577

<31.0.14-r5
  • L
GHSA-f886-m6hf-6m8v

<31.0.14-r5
  • L
GHSA-wpwq-4j6v-78m3

<31.0.14-r5
  • H
Resource Exhaustion

<31.0.14-r5
  • L
GHSA-6chq-wfr3-2hj9

<31.0.14-r5
  • L
Allocation of Resources Without Limits or Throttling

<31.0.14-r5
  • M
HTTP Response Splitting

<31.0.14-r5
  • L
GHSA-445q-vr5w-6q77

<31.0.14-r5
  • M
Improper Authentication

<31.0.14-r5
  • L
GHSA-42h9-826w-cgv3

<31.0.14-r5
  • L
Improper Input Validation

<31.0.14-r5
  • C
Unintended Proxy or Intermediary ('Confused Deputy')

<31.0.14-r5
  • L
GHSA-3w6x-2g7m-8v23

<31.0.14-r5
  • L
GHSA-pmv8-rq9r-6j72

<31.0.14-r5
  • L
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<31.0.14-r5
  • L
GHSA-j5f8-grm9-p9fc

<31.0.14-r5
  • L
GHSA-34xg-wgjx-8xph

<31.0.14-r5
  • L
GHSA-3jxr-9vmj-r5cp

<31.0.14-r5
  • L
GHSA-p92q-9vqr-4j8v

<31.0.14-r5
  • L
Improper Check for Unusual or Exceptional Conditions

<31.0.14-r5
  • L
GHSA-mmx7-hfxf-jppx

<31.0.14-r5
  • L
Information Exposure

<31.0.14-r5
  • L
GHSA-h95v-h523-3mw8

<31.0.14-r5
  • L
GHSA-f283-ghqc-fg79

<31.0.14-r5
  • C
Improperly Controlled Modification of Dynamically-Determined Object Attributes

<31.0.14-r5
  • H
Arbitrary Code Injection

<31.0.14-r5
  • L
GHSA-3g43-6gmg-66jw

<31.0.14-r5
  • L
GHSA-xhjh-pmcv-23jw

<31.0.14-r5
  • L
HTTP Response Splitting

<31.0.14-r5
  • L
GHSA-5c9x-8gcm-mpgx

<31.0.14-r5
  • L
Permissive Whitelist

<31.0.14-r5
  • L
GHSA-q8qp-cvcw-x6jj

<31.0.14-r5
  • L
CVE-2026-13149

<31.0.14-r5
  • L
GHSA-xx6v-rp6x-q39c

<31.0.14-r5
  • L
Origin Validation Error

<31.0.14-r5
  • L
GHSA-7q8q-rj6j-mhjq

<31.0.14-r5
  • L
Allocation of Resources Without Limits or Throttling

<31.0.14-r5
  • L
Improper Encoding or Escaping of Output

<31.0.14-r5
  • L
GHSA-jqh4-m9w3-8hp9

<31.0.14-r5
  • L
CRLF Injection

<31.0.14-r5
  • L
GHSA-mwf2-3pr3-8698

<31.0.14-r5
  • L
GHSA-vm85-hxw5-5432

<31.0.14-r5
  • C
Permissive Whitelist

<31.0.14-r5
  • L
GHSA-vf2m-468p-8v99

<31.0.14-r5
  • L
GHSA-94pj-82f3-465w

<31.0.14-r5
  • L
GHSA-hfxv-24rg-xrqf

<31.0.14-r5
  • L
GHSA-hq7v-mx3g-29hw

<31.0.14-r5
  • L
GHSA-cwxw-98qj-8qjx

<31.0.14-r5
  • L
GHSA-35jp-ww65-95wh

<31.0.14-r5
  • L
GHSA-g446-98w2-8p5w

<31.0.14-r5
  • L
GHSA-pmwg-cvhr-8vh7

<31.0.14-r5
  • H
Server-Side Request Forgery (SSRF)

<31.0.14-r5
  • L
GHSA-43fc-jf86-j433

<31.0.14-r5
  • H
Uncontrolled Recursion

<31.0.14-r5
  • L
GHSA-777c-7fjr-54vf

<31.0.14-r5
  • L
GHSA-hmw2-7cc7-3qxx

<31.0.14-r5
  • H
Information Exposure

<31.0.14-r5
  • L
GHSA-r4q5-vmmm-2653

<31.0.14-r5
  • L
Resource Exhaustion

<31.0.14-r5
  • L
Origin Validation Error

<31.0.14-r5
  • L
Allocation of Resources Without Limits or Throttling

<31.0.14-r5
  • L
Improper Input Validation

<31.0.14-r5
  • L
GHSA-pf86-5x62-jrwf

<31.0.14-r5
  • H
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<31.0.14-r5
  • L
Resource Exhaustion

<31.0.14-r5
  • L
GHSA-62hf-57xw-28j9

<31.0.14-r5
  • L
GHSA-m7pr-hjqh-92cm

<31.0.14-r5
  • L
GHSA-w9j2-pvgh-6h63

<31.0.14-r5
  • L
GHSA-fvcv-3m26-pcqx

<31.0.14-r5
  • L
GHSA-898c-q2cr-xwhg

<31.0.14-r5
  • L
GHSA-3p68-rc4w-qgx5

<31.0.14-r5
  • L
Missing Encryption of Sensitive Data

<31.0.14-r5
  • L
CVE-2026-12143

<31.0.14-r5
  • C
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<31.0.14-r5
  • L
GHSA-v6h2-p8h4-qcjw

<31.0.14-r5
  • L
Unintended Proxy or Intermediary ('Confused Deputy')

<31.0.14-r5
  • L
Server-Side Request Forgery (SSRF)

<31.0.14-r4
  • L
GHSA-pjwm-pj3p-43mv

<31.0.14-r4
  • L
GHSA-f7pm-6hr8-7ggm

<31.0.14-r2
  • L
Origin Validation Error

<31.0.14-r2
  • L
CVE-2025-14761

<31.0.13-r0
  • L
GHSA-x8cp-jf6f-r4xh

<31.0.13-r0
  • L
Use of Non-Canonical URL Paths for Authorization Decisions

<31.0.11-r0
  • L
GHSA-3rg7-wf37-54rm

<31.0.11-r0