{"id":"BIT-nextcloud-2026-77164","details":"Circles' remote-instance signature verification fetches the attacker-supplied keyId URL before trust in the remote instance is established, and explicitly allows local/private addresses for this request, bypassing Nextcloud's core SSRF protections. The public, unauthenticated endpoints POST /apps/circles/event/ and POST /apps/circles/incoming/ reach this code path, allowing any unauthenticated user to force the server to issue a GET request to an internal address.\n\nThe response body of the internal request is never returned to the requester, so this is blind SSRF: an attacker can determine whether an internal service is reachable, but cannot read its response contents through this endpoint alone.","aliases":["CVE-2026-77164"],"modified":"2026-09-25T14:15:15.164592754Z","published":"2026-09-25T12:27:07.203Z","database_specific":{"cpes":["cpe:2.3:a:nextcloud:nextcloud:*:*:*:*:*:*:*:*"],"severity":"Medium"},"references":[{"type":"WEB","url":"https://hackerone.com/reports/3303283"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-77164"}],"affected":[{"package":{"name":"nextcloud","ecosystem":"Bitnami","purl":"pkg:bitnami/nextcloud"},"ranges":[{"type":"SEMVER","events":[{"introduced":"31.0.0"},{"fixed":"34.0.1"}]}],"database_specific":{"source":"https://github.com/bitnami/vulndb/tree/main/data/nextcloud/BIT-nextcloud-2026-77164.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}],"schema_version":"1.9.0"}