CVE-2023-45148: Nextcloud Server

Medium severity, CVSS 4.3. EPSS: 0.7% chance of exploitation in the next 30 days.

Nextcloud is an open source home cloud server. When Memcached is used as `memcache.distributed` the rate limiting in Nextcloud Server could be reset unexpectedly resetting the rate count earlier than intended. Users are advised to upgrade to versions 25.0.11, 26.0.6 or 27.1.0. Users unable to upgrade should change their config setting `memcache.distributed` to `\OC\Memcache\Redis` and install Redis instead of Memcached.

Affected products

  • Nextcloud Nextcloud Server: from 22.0.0, before 22.2.10.16 (fixed in 22.2.10.16); from 23.0.0, before 23.0.12.11 (fixed in 23.0.12.11); from 24.0.0, before 24.0.12.7 (fixed in 24.0.12.7); from 25.0.0, before 25.0.11 (fixed in 25.0.11); from 26.0.0, before 26.0.6 (fixed in 26.0.6); version 27.0.0 only

Published 2023-10-16. Last modified 2026-06-17.