nextcloud-server-33

Direct Vulnerabilities

Known vulnerabilities in the nextcloud-server-33 package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • L
GHSA-p98j-92pf-mc4p

<33.0.9-r3
  • L
GHSA-jxrp-r7gx-q4j8

<33.0.7-r5
  • M
Cross-site Scripting (XSS)

<33.0.7-r5
  • L
CVE-2026-17495

<33.0.9-r2
  • L
GHSA-4p3w-j4w9-5jqw

<33.0.9-r2
  • L
Unintended Proxy or Intermediary ('Confused Deputy')

<33.0.9-r1
  • L
Arbitrary Code Injection

<33.0.9-r1
  • L
CVE-2026-101899

<33.0.9-r1
  • L
Resource Exhaustion

<33.0.9-r1
  • L
Resource Exhaustion

<33.0.9-r1
  • L
GHSA-r4gj-5m52-g5wh

<33.0.9-r1
  • L
GHSA-4hqw-qxg8-jxx2

<33.0.9-r1
  • L
Resource Exhaustion

<33.0.9-r1
  • L
GHSA-vh66-26gq-q6x8

<33.0.9-r1
  • L
Resource Exhaustion

<33.0.9-r1
  • L
GHSA-542g-h47m-68v8

<33.0.9-r1
  • L
GHSA-6j4f-fj2g-mc7p

<33.0.9-r1
  • L
GHSA-44g4-m2mj-wpvx

<33.0.9-r1
  • L
GHSA-3pq3-5fj3-cg6v

<33.0.9-r1
  • L
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<33.0.9-r1
  • L
GHSA-mghh-pgcx-3jjj

<33.0.9-r1
  • L
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<33.0.9-r1
  • L
GHSA-x97p-jq2g-jp4f

<33.0.9-r1
  • L
Inefficient Regular Expression Complexity

<33.0.9-r1
  • L
GHSA-qhr7-859c-m2p7

<33.0.9-r1
  • L
Server-Side Request Forgery (SSRF)

<33.0.9-r1
  • L
Unintended Proxy or Intermediary ('Confused Deputy')

<33.0.9-r1
  • L
GHSA-m8m8-qj5v-23w3

<33.0.9-r1
  • L
Resource Exhaustion

<33.0.9-r1
  • L
Arbitrary Code Injection

<33.0.9-r1
  • L
GHSA-j8rh-479h-cp32

<33.0.9-r1
  • L
GHSA-q2hr-2g5m-vwhr

<33.0.9-r1
  • L
GHSA-c29m-xwm3-cm6r

<33.0.9-r1
  • L
GHSA-9fr6-4gfg-395g

<33.0.9-r1
  • L
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<33.0.9-r1
  • L
GHSA-3mcp-22mf-vrw3

<33.0.6-r8
  • H
Uncontrolled Recursion

<33.0.6-r8
  • L
GHSA-vcc3-ghjq-m6fr

<33.0.8-r3
  • L
CVE-2026-45822

<33.0.8-r3
  • L
GHSA-68jp-44vc-2x5h

<33.0.6-r8
  • L
GHSA-fq2j-3j99-rx65

<33.0.6-r8
  • H
Information Exposure

<33.0.6-r8
  • H
Permissive Whitelist

<33.0.6-r8
  • H
Allocation of Resources Without Limits or Throttling

<33.0.6-r8
  • L
GHSA-9wx3-p993-35vp

<33.0.6-r8
  • L
GHSA-39j5-w47m-2gmv

<33.0.6-r8
  • L
GHSA-6hqm-hm2v-3p2p

<33.0.6-r8
  • L
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<33.0.6-r8
  • H
Resource Exhaustion

<33.0.6-r8
  • M
Resource Exhaustion

<33.0.6-r8
  • L
GHSA-fqj3-h9pc-443h

<33.0.6-r8
  • H
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<33.0.6-r8
  • L
GHSA-4ww2-rjh2-xpv9

<33.0.6-r8
  • H
Resource Exhaustion

<33.0.6-r8
  • L
GHSA-f2r5-pqh9-r8f8

<33.0.6-r8
  • L
GHSA-pcw8-m77r-2528

<33.0.6-r9
  • L
Directory Traversal

<33.0.8-r1
  • L
GHSA-fxqj-rqcc-2cmp

<33.0.8-r1
  • L
GHSA-r28c-9q8g-f849

<33.0.8-r1
  • M
Directory Traversal

<33.0.8-r1
  • L
GHSA-c2j3-45gr-mqc4

<33.0.7-r5
  • L
GHSA-6g55-p6wh-862q

<33.0.7-r4
  • C
Directory Traversal

<33.0.7-r4
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<33.0.7-r3
  • L
GHSA-2v37-7h3g-55p8

<33.0.7-r3
  • L
Resource Exhaustion

<33.0.7-r3
  • L
GHSA-28wg-ghj8-5hjv

<33.0.7-r3
  • L
GHSA-55q2-fjhq-7xh7

<33.0.7-r5
  • L
GHSA-rgw5-rvv9-x895

<33.0.7-r3
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<33.0.7-r3
  • M
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<33.0.6-r8
  • L
GHSA-38gx-cfqf-f652

<33.0.6-r8
  • L
GHSA-mjrx-74jh-7xgw

<33.0.6-r8
  • L
GHSA-mqq9-gxg5-m58g

<33.0.6-r8
  • M
Information Exposure

<33.0.6-r8
  • M
Information Exposure

<33.0.6-r8
  • M
Information Exposure

<33.0.6-r8
  • L
GHSA-32rq-jhr7-m3hh

<33.0.6-r8
  • M
Allocation of Resources Without Limits or Throttling

<33.0.6-r8
  • L
GHSA-3fvr-2jw6-crq4

<33.0.6-r8
  • L
CVE-2026-14257

<33.0.7-r2
  • L
GHSA-mh99-v99m-4gvg

<33.0.7-r2
  • L
GHSA-xvcm-6775-5m9r

<33.0.7-r1
  • L
Algorithmic Complexity

<33.0.7-r1
  • L
GHSA-v56q-mh7h-f735

<33.0.7-r1
  • L
Integer Overflow or Wraparound

<33.0.7-r1
  • M
Trust Boundary Violation

<33.0.6-r0
  • H
Cross-site Scripting (XSS)

<33.0.6-r5
  • M
Protection Mechanism Failure

<33.0.6-r5
  • M
Insufficient Comparison

<33.0.6-r0
  • M
Cross-site Scripting (XSS)

<33.0.6-r0
  • M
Cross-site Scripting (XSS)

<33.0.6-r0
  • L
Improper Input Validation

<33.0.6-r9
  • L
GHSA-378v-28hj-76wf

<33.0.6-r9
  • L
GHSA-w5hq-g745-h8pq

<33.0.6-r9
  • H
Out-of-bounds Write

<33.0.6-r9
  • L
GHSA-rf66-hmqf-q3fc

<33.0.6-r9
  • M
Cross-site Scripting (XSS)

<33.0.6-r9
  • L
GHSA-3jxr-9vmj-r5cp

<33.0.6-r9
  • L
CVE-2026-2739

<33.0.6-r9
  • L
CVE-2026-13149

<33.0.6-r9
  • L
GHSA-94pj-82f3-465w

<33.0.6-r8
  • L
GHSA-h95v-h523-3mw8

<33.0.6-r8
  • L
GHSA-mmx7-hfxf-jppx

<33.0.6-r8
  • L
GHSA-7q8q-rj6j-mhjq

<33.0.6-r8
  • L
GHSA-mwf2-3pr3-8698

<33.0.6-r8
  • L
GHSA-f4gw-2p7v-4548

<33.0.6-r8
  • L
GHSA-gcfj-64vw-6mp9

<33.0.6-r8
  • L
GHSA-pmv8-rq9r-6j72

<33.0.6-r8
  • L
GHSA-xj6q-8x83-jv6g

<33.0.6-r8
  • L
GHSA-jqh4-m9w3-8hp9

<33.0.6-r8
  • L
GHSA-wm3w-8rrp-j577

<33.0.6-r8
  • L
GHSA-42h9-826w-cgv3

<33.0.6-r8
  • L
GHSA-hcpx-6fm6-wx23

<33.0.6-r8
  • L
GHSA-f283-ghqc-fg79

<33.0.6-r8
  • H
Resource Exhaustion

<33.0.6-r7
  • L
GHSA-f886-m6hf-6m8v

<33.0.6-r7
  • L
GHSA-qx2v-qp2m-jg93

<33.0.6-r6
  • L
Cross-site Scripting (XSS)

<33.0.6-r6
  • L
GHSA-vxr8-fq34-vvx9

<33.0.6-r5
  • L
GHSA-cmwh-pvxp-8882

<33.0.6-r5
  • L
Server-Side Request Forgery (SSRF)

<33.0.5-r3
  • L
CVE-2026-12143

<33.0.6-r3
  • L
GHSA-hmw2-7cc7-3qxx

<33.0.6-r3
  • L
GHSA-mw96-cpmx-2vgc

<33.0.6-r4
  • L
GHSA-fx2h-pf6j-xcff

<33.0.6-r2
  • L
GHSA-v6wh-96g9-6wx3

<33.0.6-r2
  • C
Directory Traversal

<33.0.6-r4
  • L
Directory Traversal

<33.0.6-r2
  • L
External Control of File Name or Path

<33.0.6-r2
  • L
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<33.0.6-r1
  • L
GHSA-c2c7-rcm5-vvqj

<33.0.6-r1
  • L
GHSA-3v7f-55p6-f55p

<33.0.6-r1
  • L
Inefficient Regular Expression Complexity

<33.0.6-r1
  • C
Improperly Controlled Modification of Dynamically-Determined Object Attributes

<33.0.6-r0
  • L
Improper Check for Unusual or Exceptional Conditions

<33.0.6-r0
  • L
GHSA-hfxv-24rg-xrqf

<33.0.6-r0
  • L
Allocation of Resources Without Limits or Throttling

<33.0.6-r0
  • L
GHSA-898c-q2cr-xwhg

<33.0.6-r0
  • L
GHSA-xhjh-pmcv-23jw

<33.0.6-r0
  • L
Permissive Whitelist

<33.0.6-r0
  • L
GHSA-38cx-cq6f-5755

<33.0.5-r4
  • L
Origin Validation Error

<33.0.5-r3
  • L
Cross-site Scripting (XSS)

<33.0.6-r0
  • L
GHSA-34xg-wgjx-8xph

<33.0.5-r3
  • L
Incomplete Blacklist

<33.0.5-r4
  • L
GHSA-gvmj-g25r-r7wr

<33.0.6-r0
  • L
Cross-site Scripting (XSS)

<33.0.6-r0
  • M
Cross-site Scripting (XSS)

<33.0.6-r0
  • M
HTTP Response Splitting

<33.0.6-r0
  • L
GHSA-3p68-rc4w-qgx5

<33.0.6-r0
  • L
Server-Side Request Forgery (SSRF)

<33.0.6-r0
  • L
GHSA-3w6x-2g7m-8v23

<33.0.6-r0
  • L
GHSA-w9j2-pvgh-6h63

<33.0.6-r0
  • L
GHSA-35jp-ww65-95wh

<33.0.6-r0
  • L
GHSA-pf86-5x62-jrwf

<33.0.6-r0
  • L
Improper Input Validation

<33.0.5-r3
  • L
GHSA-hq7v-mx3g-29hw

<33.0.5-r3
  • L
GHSA-pjwm-pj3p-43mv

<33.0.6-r0
  • H
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<33.0.6-r0
  • H
Arbitrary Code Injection

<33.0.6-r0
  • L
CRLF Injection

<33.0.6-r0
  • L
GHSA-vf2m-468p-8v99

<33.0.6-r0
  • L
Information Exposure

<33.0.6-r0
  • L
GHSA-r47g-fvhr-h676

<33.0.6-r0
  • C
Permissive Whitelist

<33.0.6-r0
  • L
GHSA-m557-wrgg-6rp4

<33.0.5-r3
  • L
GHSA-wpwq-4j6v-78m3

<33.0.5-r3
  • L
GHSA-crv5-9vww-q3g8

<33.0.6-r0
  • C
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<33.0.6-r0
  • M
Cross-site Scripting (XSS)

<33.0.6-r0
  • L
GHSA-62hf-57xw-28j9

<33.0.6-r0
  • L
GHSA-43fc-jf86-j433

<33.0.6-r0
  • L
Improper Input Validation

<33.0.5-r3
  • L
Cross-site Scripting (XSS)

<33.0.6-r0
  • L
GHSA-m7pr-hjqh-92cm

<33.0.6-r0
  • L
Resource Exhaustion

<33.0.6-r0
  • L
GHSA-h7mw-gpvr-xq4m

<33.0.6-r0
  • C
Unintended Proxy or Intermediary ('Confused Deputy')

<33.0.6-r0
  • L
GHSA-5c9x-8gcm-mpgx

<33.0.6-r0
  • L
GHSA-cwxw-98qj-8qjx

<33.0.5-r3
  • L
GHSA-76mc-f452-cxcm

<33.0.6-r0
  • L
Allocation of Resources Without Limits or Throttling

<33.0.6-r0
  • L
Missing Encryption of Sensitive Data

<33.0.5-r3
  • L
GHSA-777c-7fjr-54vf

<33.0.6-r0
  • L
GHSA-xx6v-rp6x-q39c

<33.0.6-r0
  • L
HTTP Response Splitting

<33.0.6-r0
  • L
GHSA-3g43-6gmg-66jw

<33.0.6-r0
  • L
GHSA-q8qp-cvcw-x6jj

<33.0.6-r0
  • L
Uncontrolled Recursion

<33.0.6-r0
  • L
GHSA-hpcv-96wg-7vj8

<33.0.6-r0
  • H
Uncontrolled Recursion

<33.0.6-r0
  • L
GHSA-39q2-94rc-95cp

<33.0.6-r0
  • H
Server-Side Request Forgery (SSRF)

<33.0.6-r0
  • L
GHSA-pmwg-cvhr-8vh7

<33.0.6-r0
  • H
Information Exposure

<33.0.6-r0
  • L
GHSA-rp9w-3fw7-7cwq

<33.0.6-r0
  • L
GHSA-v9jr-rg53-9pgp

<33.0.6-r0
  • L
Allocation of Resources Without Limits or Throttling

<33.0.6-r0
  • L
Improper Encoding or Escaping of Output

<33.0.6-r0
  • L
GHSA-48c2-rrv3-qjmp

<33.0.6-r0
  • L
GHSA-x4vx-rjvf-j5p4

<33.0.6-r0
  • L
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<33.0.6-r0
  • M
Improper Authentication

<33.0.6-r0
  • L
Unintended Proxy or Intermediary ('Confused Deputy')

<33.0.6-r0
  • L
GHSA-j5f8-grm9-p9fc

<33.0.6-r0
  • L
Cross-site Scripting (XSS)

<33.0.6-r0
  • L
GHSA-p92q-9vqr-4j8v

<33.0.6-r0
  • L
GHSA-fvcv-3m26-pcqx

<33.0.6-r0
  • L
GHSA-vm85-hxw5-5432

<33.0.5-r3
  • L
GHSA-6chq-wfr3-2hj9

<33.0.6-r0
  • L
GHSA-r4q5-vmmm-2653

<33.0.6-r0
  • L
CRLF Injection

<33.0.5-r3
  • L
GHSA-445q-vr5w-6q77

<33.0.6-r0
  • L
GHSA-x6g4-fwcc-jj8w

<33.0.5-r2
  • L
GHSA-vqc8-7275-q272

<33.0.5-r2
  • H
Arbitrary Argument Injection

<33.0.5-r2
  • L
Incorrect Regular Expression

<33.0.5-r2
  • L
GHSA-qpmx-3rfj-7rhv

<33.0.5-r2
  • L
CRLF Injection

<33.0.5-r2
  • M
CRLF Injection

<33.0.5-r2
  • L
GHSA-xx3c-qf5g-hc39

<33.0.5-r2
  • L
Improper Validation of Unsafe Equivalence in Input

<33.0.5-r2
  • L
GHSA-2xf4-cg6j-vhgq

<33.0.5-r2
  • H
XML External Entity (XXE) Injection

<33.0.5-r2
  • L
GHSA-72xp-p242-47p9

<33.0.5-r2
  • L
GHSA-3qpq-r242-jqj7

<33.0.3-r1
  • L
Resource Exhaustion

<33.0.3-r1
  • L
GHSA-r854-jrxh-36qx

<33.0.3-r0
  • L
GHSA-27qh-8cxx-2cr5

<33.0.3-r0
  • L
GHSA-94g3-g5v7-q4jg

<33.0.3-r0
  • L
Information Exposure

<33.0.3-r0
  • M
Information Exposure

<33.0.3-r0
  • L
GHSA-x92j-g74p-p2hq

<33.0.2-r1
  • L
GHSA-46fq-v4pg-gr3j

<33.0.2-r1
  • L
GHSA-qqc2-7f54-r7wp

<33.0.2-r1
  • L
Arbitrary Argument Injection

<33.0.1-r0
  • L
GHSA-r39x-jcww-82v6

<33.0.1-r0
  • L
Origin Validation Error

<33.0.0-r1
  • L
GHSA-f7pm-6hr8-7ggm

<33.0.0-r1