--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-5c1bbb46c3
2026-09-28 00:14:46.769083+00:00
--------------------------------------------------------------------------------

Name        : nextcloud
Product     : Fedora 45
Version     : 34.0.4
Release     : 1.fc45
URL         : http://nextcloud.com
Summary     : Private file sync and share server
Description :
NextCloud gives you universal access to your files through a web interface or
WebDAV. It also provides a platform to easily view & sync your contacts,
calendars and bookmarks across all your devices and enables basic editing right
on the web. NextCloud is extendable via a simple but powerful API for
applications and plugins.

--------------------------------------------------------------------------------
Update Information:

34.0.4 Release
--------------------------------------------------------------------------------
ChangeLog:

* Sat Sep 19 2026 Andrew Bauer <[email protected]> - 34.0.4-1
- 34.0.4 Release
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #2526255 - CVE-2026-48988 nextcloud: markdown-it: Denial of Service 
via quadratic processing of smartquotes with typographer enabled [epel-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=2526255
  [ 2 ] Bug #2526261 - CVE-2026-48988 nextcloud: markdown-it: Denial of Service 
via quadratic processing of smartquotes with typographer enabled [fedora-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=2526261
  [ 3 ] Bug #2527333 - CVE-2026-82562 nextcloud: qs: Denial of Service via 
array limit bypass in query string parsing [fedora-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=2527333
  [ 4 ] Bug #2527355 - CVE-2026-82562 nextcloud: qs: Denial of Service via 
array limit bypass in query string parsing [epel-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=2527355
  [ 5 ] Bug #2527907 - CVE-2026-82417 nextcloud: qs: Denial of Service via 
improper validation in stringify function [epel-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=2527907
  [ 6 ] Bug #2527912 - CVE-2026-82417 nextcloud: qs: Denial of Service via 
improper validation in stringify function [fedora-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=2527912
  [ 7 ] Bug #2534968 - nextcloud-35.0.0 is available
        https://bugzilla.redhat.com/show_bug.cgi?id=2534968
  [ 8 ] Bug #2535906 - CVE-2026-75838 nextcloud: DOMPurify: Cross-Site 
Scripting via IN_PLACE sanitization [fedora-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=2535906
  [ 9 ] Bug #2535908 - CVE-2026-75838 nextcloud: DOMPurify: Cross-Site 
Scripting via IN_PLACE sanitization [epel-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=2535908
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-5c1bbb46c3' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------

-- 
_______________________________________________
package-announce mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/[email protected]
Do not reply to spam, report it: 
https://forge.fedoraproject.org/infra/tickets/issues/new

Reply via email to