
Fedora released security fixes for NextCloud addressing CVE-2026-42044 (Axios JSON response tampering via prototype pollution) and CVE-2026-44167 (phpseclib ASN.1 DoS) in versions before 33.0.4, Linuxsecurity reported. https://threatcluster.io/cluster/fedora-nextcloud-update-addresses-json-tampering-and-dos-vul-6d508800
Post summary
Fedora has issued patches for NextCloud vulnerabilities CVE-2026-42044 and CVE-2026-44167, addressing prototype‑pollution JSON tampering and an ASN.1‑based DoS flaw.

