CVE-2023-35173: Nextcloud End-To-End Encryption

Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.

Nextcloud End-to-end encryption app provides all the necessary APIs to implement End-to-End encryption on the client side. By providing an invalid meta data file, an attacker can make previously dropped files inaccessible. It is recommended that the Nextcloud End-to-end encryption app is upgraded to version 1.12.4 that contains the fix.

Affected products

  • Nextcloud End-To-End Encryption: from 1.12.0, before 1.12.4 (fixed in 1.12.4)

Published 2023-06-23. Last modified 2026-06-17.