
Fedora released security fixes for NextCloud addressing CVE-2026-42044 (Axios JSON response tampering via prototype pollution) and CVE-2026-44167 (phpseclib ASN.1 DoS) in versions before 33.0.4, Linuxsecurity reported. https://threatcluster.io/cluster/fedora-nextcloud-update-addresses-json-tampering-and-dos-vul-6d508800
Post summary
Fedora updated NextCloud to address two vulnerabilities—prototype pollution in Axios JSON response handling and an ASN.1 DoS via phpseclib—without any mention of active exploitation or proof‑of‑concepts.

