Low severity3.7NVD Advisory· Published Feb 13, 2023· Updated Jun 17, 2026
CVE-2023-25161
CVE-2023-25161
Description
Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Nextcloud Server and Nextcloud Enterprise Server prior to versions 25.0.1 24.0.8, and 23.0.12 missing rate limiting on password reset functionality. This could result in service slowdown, storage overflow, or cost impact when using external email services. Users should upgrade to Nextcloud Server 25.0.1, 24.0.8, or 23.0.12 or Nextcloud Enterprise Server 25.0.1, 24.0.8, or 23.0.12 to receive a patch. No known workarounds are available.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- Range: prior to 25.0.1, 24.0.8, and 23.0.12
- Range: = 25.0.0
Patches
Vulnerability mechanics
References
3- github.com/nextcloud/server/pull/34632nvdIssue TrackingPatch
- github.com/nextcloud/security-advisories/security/advisories/GHSA-492h-596q-xr2fnvdVendor Advisory
- hackerone.com/reports/1691195nvdPermissions RequiredThird Party Advisory
News mentions
0No linked articles in our index yet.