CVE-2023-28644: Nextcloud Server
High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.
Nextcloud server is an open source home cloud implementation. In releases of the 25.0.x branch before 25.0.3 an inefficient fetch operation may impact server performances and/or can lead to a denial of service. This issue has been addressed and it is recommended that the Nextcloud Server is upgraded to 25.0.3. There are no known workarounds for this vulnerability.
Affected products
- Nextcloud Nextcloud Server: from 25.0.0, before 25.0.3 (fixed in 25.0.3)
Published 2023-03-30. Last modified 2026-06-17.