VYPR
Low severity3.5NVD Advisory· Published Oct 25, 2021· Updated Jun 17, 2026

CVE-2021-39220

CVE-2021-39220

Description

Nextcloud is an open-source, self-hosted productivity platform The Nextcloud Mail application prior to versions 1.10.4 and 1.11.0 does by default not render images in emails to not leak the read state or user IP. The privacy filter failed to filter images with a relative protocol. It is recommended that the Nextcloud Mail application is upgraded to 1.10.4 or 1.11.0. There are no known workarounds aside from upgrading.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • nextcloud/security-advisoriesv5
    Range: < 1.10.4, < 1.11.0
  • Range: <1.10.4, <1.11.0
  • cpe:2.3:a:nextcloud:mail:*:*:*:*:*:*:*:*
    Range: <1.10.4

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.