CVE-2026-44515

Source
https://cve.org/CVERecord?id=CVE-2026-44515
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-44515.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-44515
Aliases
  • GHSA-jcfr-rmj6-cpfj
Published
2026-05-14T16:36:11Z
Modified
2026-08-12T03:51:09Z
Severity
  • 2.3 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N CVSS Calculator
Summary
Nextcloud News: Authenticated blind SSRF via feed URL
Details

Nextcloud News is an RSS/Atom feed reader. Prior to 28.3.0-beta.1, Nextcloud News allows authenticated users to add feeds by providing a feed URL (via the web interface or the API). In affected versions, an authenticated attacker could provide a URL pointing to internal/private IP ranges or localhost, causing the Nextcloud server to perform server-side HTTP requests to attacker-controlled destinations, but not relaying the result. This enables blind SSRF, which can be used to scan or probe internal network services that are reachable from the Nextcloud server. This vulnerability is fixed in 28.3.0-beta.1.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-918"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/44xxx/CVE-2026-44515.json"
}
References

Affected packages

Git / github.com/nextcloud/news

Affected ranges

Type
GIT
Repo
https://github.com/nextcloud/news
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "28.3.0-beta.1"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

1.*
1.001
1.201
1.203
1.204
1.206
1.401
1.603
1.604
1.605
1.801
1.802
1.803
1.804
1.805
1.806
1.807
1.808
10.*
10.0.0
10.1.0
10.2.0
11.*
11.0.0
11.0.1
11.0.2
11.0.3
11.0.4
11.0.5
12.*
12.0.0
12.0.1
12.0.2
12.0.3
12.0.4
13.*
13.0.0
13.0.1
13.0.2
13.0.3
13.1.0
13.1.1
13.1.2
13.1.3
13.1.4
13.1.5
13.1.6
14.*
14.0.0
14.0.1
14.0.2
14.1.0
14.1.1
14.1.10
14.1.11
14.1.2
14.1.3
14.1.4
14.1.4-rc1
14.1.5
14.1.6
14.1.7
14.1.8
14.1.9
14.2.0
14.2.1
14.2.2
15.*
15.0.0
15.0.1
15.0.2
15.0.3
15.0.4
15.0.5
15.0.6
15.0.6-rc1
15.0.6-rc2
15.0.6-rc3
15.0.6-rc4
15.0.6-rc5
15.1.0
15.1.0-rc1
15.1.0-rc2
15.1.0-rc3
15.1.1
15.1.1-rc1
15.1.1-rc2
15.2.0
15.2.0-beta1
15.2.0-beta2
15.2.0-rc1
15.2.1
15.2.2
15.3.0
15.3.1
15.3.1-rc1
15.3.1-rc2
15.3.1-rc3
15.3.2
15.3.2-rc1
15.3.2-rc2
15.4.0-beta1
15.4.0-beta2
15.4.0-beta3
15.4.0-beta4
16.*
16.0.0
16.0.0-beta1
16.0.0-beta2
16.0.0-beta3
16.1.0
16.1.0-beta1
16.2.0
16.2.0-beta1
16.2.0-beta2
16.2.1
17.*
17.0.0
17.0.0-beta1
17.0.1
18.*
18.0.0
18.0.0-beta1
18.0.1
18.0.1-beta1
18.0.1-beta2
18.0.1-beta3
18.1.0
18.1.0-beta1
18.1.0-beta2
18.1.1
18.1.1-beta1
18.2.0
18.2.0-beta1
18.2.0-beta2
18.3.0
18.3.0-beta1
19.*
19.0.0
19.0.0-beta1
19.0.0-beta2
19.0.1
20.*
20.0.0
20.0.1
21.*
21.0.0
21.0.0-beta1
21.1.0
21.1.0-beta1
21.2.0
21.2.0-beta1
21.2.0-beta2
21.2.0-beta3
21.2.0-beta4
22.*
22.0.0
22.0.0-beta1
22.0.0-beta2
23.*
23.0.0
23.0.0-beta1
24.*
24.0.0
24.0.0-beta1
25.*
25.0.0
25.0.0-alpha1
25.0.0-alpha10
25.0.0-alpha11
25.0.0-alpha12
25.0.0-alpha13
25.0.0-alpha14
25.0.0-alpha2
25.0.0-alpha3
25.0.0-alpha4
25.0.0-alpha5
25.0.0-alpha6
25.0.0-alpha7
25.0.0-alpha8
25.0.0-alpha9
25.0.1
25.0.2
25.0.3
25.1.0
25.1.1
25.1.2
25.2.0
25.2.0-beta.1
25.2.0-beta.2
25.2.0-beta.3
25.2.1
25.2.1-beta.1
25.2.1-beta.2
25.3.0
25.3.0-beta.1
25.3.0-beta.2
25.3.1
26.*
26.0.0
26.0.0-beta.1
26.0.0-beta.2
26.0.0-beta.3
26.0.0-beta.4
26.0.0-beta.5
26.0.1
26.0.2
26.1.0
26.1.0-beta.1
27.*
27.0.0
27.0.0-beta.1
27.0.1
27.1.0
27.2.0
27.2.0-beta.1
27.2.0-beta.2
27.2.0-beta.3
28.*
28.0.0
28.0.0-beta.1
28.0.0-beta.2
28.0.0-beta.3
28.0.0-rc.1
28.0.0-rc.2
28.0.1
28.1.0
28.2.0
28.2.0-beta.1
28.2.0-beta.2
3.*
3.001
3.002
3.003
3.101
3.102
3.103
3.104
3.105
3.201
3.202
3.301
3.302
3.401
3.402
3.403
3.404
3.405
3.406
4.*
4.0.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1.0
4.1.1
4.1.2
4.1.3
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.3.0
4.3.1
4.3.2
5.*
5.0.0
5.0.1
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.3.0
5.3.1
5.3.2
5.3.3
5.3.4
5.3.5
5.3.7
5.3.8
5.3.9
6.*
6.0.0
6.0.1
6.0.3
6.0.4
6.0.5
6.1.0
6.1.1
7.*
7.0.0
7.0.1
7.1.0
7.1.1
7.1.2
8.*
8.0.0
8.1.0
8.2.0
8.3.0
8.4.0
8.4.1
8.5.0
8.6.0
8.7.0
8.7.1
8.7.3
8.7.4
8.7.5
8.8.0
8.8.3
9.*
9.0.0
9.0.1
9.0.2
9.0.3
9.0.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-44515.json"