Bug 2510264 - CVE-2026-67316 nextcloud: axios: Prototype Pollution allows unauthorized data transmission and network redirection [epel-all]
Summary: CVE-2026-67316 nextcloud: axios: Prototype Pollution allows unauthorized data...
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Fedora EPEL
Classification: Fedora
Component: nextcloud
Version: epel10
Hardware: Unspecified
OS: Unspecified
low
low
Target Milestone: ---
Assignee: Andrew Bauer
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard: {"flaws": ["aadd2b7c-a7c3-4b86-82a3-a...
Depends On:
Blocks: CVE-2026-67316
TreeView+ depends on / blocked
 
Reported: 2026-08-03 04:07 UTC by Ganesh
Modified: 2026-08-25 01:15 UTC (History)
2 users (show)

Fixed In Version: nextcloud-34.0.3-1.el10_2 nextcloud-34.0.3-1.fc44 nextcloud-34.0.3-1.el10_3 nextcloud-34.0.3-1.fc43
Clone Of:
Environment:
Last Closed: 2026-08-25 00:27:34 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Ganesh 2026-08-03 04:07:05 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

axios is vulnerable to read-side prototype-pollution gadgets that can alter request construction when Object.prototype has already been polluted by a separate vulnerability or dependency. In the bodyless method aliases (axios.get(), axios.delete(), axios.head(), axios.options()), inherited data is read via (config || {}).data before config normalization, causing an attacker-controlled body to be sent on requests that did not set one. Additional low-level paths, only reachable when calling exported adapters/helpers (e.g. lib/adapters/http.js, unsafe/helpers/resolveConfig.js) directly with plain configs and no own proxy or paramsSerializer, can inherit polluted proxy values (routing requests through an attacker-controlled proxy) or paramsSerializer values (attacker-controlled URL serialization). These low-level gadgets do not reproduce through normal high-level axios calls on 1.15.2+. The issue is fixed in axios 1.18.0 and 0.33.0.

Comment 1 Fedora Update System 2026-08-16 21:15:28 UTC
FEDORA-EPEL-2026-b2421df34a (nextcloud-34.0.3-1.el10_3) has been submitted as an update to Fedora EPEL 10.3.
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-b2421df34a

Comment 2 Fedora Update System 2026-08-16 21:17:13 UTC
FEDORA-2026-a1368a72b4 (nextcloud-34.0.3-1.fc44) has been submitted as an update to Fedora 44.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-a1368a72b4

Comment 3 Fedora Update System 2026-08-16 21:17:46 UTC
FEDORA-2026-625cbe86c8 (nextcloud-34.0.3-1.fc43) has been submitted as an update to Fedora 43.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-625cbe86c8

Comment 4 Fedora Update System 2026-08-16 21:22:00 UTC
FEDORA-EPEL-2026-15025fbfe6 (nextcloud-34.0.3-1.el10_2) has been submitted as an update to Fedora EPEL 10.2.
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-15025fbfe6

Comment 5 Fedora Update System 2026-08-17 01:17:32 UTC
FEDORA-EPEL-2026-15025fbfe6 has been pushed to the Fedora EPEL 10.2 testing repository.

You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-15025fbfe6

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 6 Fedora Update System 2026-08-17 01:31:22 UTC
FEDORA-2026-a1368a72b4 has been pushed to the Fedora 44 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-a1368a72b4`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2026-a1368a72b4

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 7 Fedora Update System 2026-08-17 01:33:28 UTC
FEDORA-EPEL-2026-b2421df34a has been pushed to the Fedora EPEL 10.3 testing repository.

You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-b2421df34a

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 8 Fedora Update System 2026-08-17 01:50:38 UTC
FEDORA-2026-625cbe86c8 has been pushed to the Fedora 43 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-625cbe86c8`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2026-625cbe86c8

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 9 Fedora Update System 2026-08-25 00:27:34 UTC
FEDORA-EPEL-2026-15025fbfe6 (nextcloud-34.0.3-1.el10_2) has been pushed to the Fedora EPEL 10.2 stable repository.
If problem still persists, please make note of it in this bug report.

Comment 10 Fedora Update System 2026-08-25 01:01:56 UTC
FEDORA-2026-a1368a72b4 (nextcloud-34.0.3-1.fc44) has been pushed to the Fedora 44 stable repository.
If problem still persists, please make note of it in this bug report.

Comment 11 Fedora Update System 2026-08-25 01:06:54 UTC
FEDORA-EPEL-2026-b2421df34a (nextcloud-34.0.3-1.el10_3) has been pushed to the Fedora EPEL 10.3 stable repository.
If problem still persists, please make note of it in this bug report.

Comment 12 Fedora Update System 2026-08-25 01:15:42 UTC
FEDORA-2026-625cbe86c8 (nextcloud-34.0.3-1.fc43) has been pushed to the Fedora 43 stable repository.
If problem still persists, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.