Junglewise Threat Intelligence

CVE-2026-44515: Nextcloud News blind SSRF via feed URL

CVE-2026-44515 · Severity: info · CVSS 2.3 · Published 2026-05-14

Vendors: Nextcloud.

Executive brief

Nextcloud News is an RSS/Atom feed reader application. A security flaw allows logged-in users to force the server to make requests to internal network addresses or local services that should normally be private. While the attacker cannot see the content of the internal responses, they can use this to map out and probe the organization's internal infrastructure, potentially identifying further targets for attack.

Technical details

A blind Server-Side Request Forgery (SSRF) vulnerability exists in the Nextcloud News application due to insufficient validation of user-supplied feed URLs. Authenticated attackers can provide URLs pointing to internal IP ranges or localhost via the web interface or API. The server then attempts to fetch these URLs, performing HTTP requests to internal destinations. While the application does not return the response body to the attacker, the vulnerability can be exploited to perform internal port scanning or service discovery based on response timing and application behavior. The issue is addressed in version 28.3.0-beta.1 by implementing stricter URL validation.

Affected products

  • Nextcloud News < 28.3.0-beta.1

Timeline

  • 2026-05-01: advisory: GitHub Security Advisory published
  • 2026-05-14: disclosed: CVE published to NVD

References