CVE-2023-48307: Nextcloud Mail
Critical severity, CVSS 9.8. EPSS: 0.9% chance of exploitation in the next 30 days.
Nextcloud Mail is the mail app for Nextcloud, a self-hosted productivity platform. Starting in version 1.13.0 and prior to version 2.2.8 and 3.3.0, an attacker can use an unprotected endpoint in the Mail app to perform a SSRF attack. Nextcloud Mail app versions 2.2.8 and 3.3.0 contain a patch for this issue. As a workaround, disable the mail app.
Affected products
- Nextcloud Mail: from 1.13.0, before 2.2.8 (fixed in 2.2.8); from 3.0.0, before 3.3.0 (fixed in 3.3.0)
Published 2023-11-21. Last modified 2026-06-17.