Low severity3.5NVD Advisory· Published Oct 25, 2021· Updated Jun 17, 2026
CVE-2021-39220
CVE-2021-39220
Description
Nextcloud is an open-source, self-hosted productivity platform The Nextcloud Mail application prior to versions 1.10.4 and 1.11.0 does by default not render images in emails to not leak the read state or user IP. The privacy filter failed to filter images with a relative protocol. It is recommended that the Nextcloud Mail application is upgraded to 1.10.4 or 1.11.0. There are no known workarounds aside from upgrading.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- nextcloud/security-advisoriesv5Range: < 1.10.4, < 1.11.0
Patches
Vulnerability mechanics
References
3- github.com/nextcloud/mail/pull/5470nvdPatchThird Party Advisory
- github.com/nextcloud/security-advisories/security/advisories/GHSA-6q9v-wm8r-rcv5nvdThird Party Advisory
- hackerone.com/reports/1308147nvdPermissions Required
News mentions
0No linked articles in our index yet.