CVE-2025-47791: Nextcloud Server's test remote endpoint is not rate limited
Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server prior to 28.0.13, 29.0.10, and 30.0.3 and Nextcloud Enterprise Server prior to 28.0.13, 29.0.10, and 30.0.3, a currently unused endpoint to verify a share recipient was not protected correctly, allowing to proxy requests to another server. The endpoint was removed in Nextcloud Server 28.0.13, 29.0.10, and 30.0.3 and Nextcloud Enterprise Server 28.0.13, 29.0.10, and 30.0.3. No known workarounds are available.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-47791?
CVE-2025-47791 is classified as a high severity vulnerability affecting Nextcloud Server and Enterprise Server.
How do I fix CVE-2025-47791?
To mitigate CVE-2025-47791, update Nextcloud Server or Enterprise Server to versions 28.0.13, 29.0.10, or 30.0.3 or later.
What impact does CVE-2025-47791 have on my Nextcloud instance?
CVE-2025-47791 could allow unauthorized access to verify share recipients, potentially exposing sensitive data.
Which versions of Nextcloud are affected by CVE-2025-47791?
Versions of Nextcloud prior to 28.0.13, 29.0.10, and 30.0.3 are vulnerable to CVE-2025-47791.
Is CVE-2025-47791 being actively exploited?
As of the latest updates, there are no specific reports confirming active exploitation of CVE-2025-47791.