
A Reddit homelab owner's self-hosted Nextcloud got compromised through CVE-2025-66208, a critical, unauthenticated command-injection bug in the bundled document server — reachable only because their reverse proxy trusted a header it shouldn't have. 792 upvotes, still climbing. "Self-hosted" and "safe" are two separate claims, and the second one depends on config choices most people never audit. When did you last actually check your reverse proxy config instead of assuming the defaults were fine?
