Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Per CVE-2025-15599 documentation, this issue was fixed in DomPurify 3.2.7. https://nvd.nist.gov/vuln/detail/CVE-2025-15599 The current version of Nextcloud 32.0.6 in fedora repos ships with DOMPurify 3.3.0. Consequently, this bug is invalid.