Impact
Circles’ remote‑instance signature verification performs a GET request to an attacker‑supplied keyId URL before authentication, and intentionally permits local or private addresses for this request. Public, unauthenticated endpoints POST /apps/circles/event/ and POST /apps/circles/incoming/ trigger this code path, giving any unauthenticated user the ability to cause the server to send a blind internal request. The response body is never returned, so the flaw provides only reconnaissance capability—an attacker can learn whether a service is reachable internally but cannot read its data directly.
Affected Systems
The vulnerability is present in Nextcloud Server, specifically within the Circles app. No specific version range is listed in the CNA data, so any deployed instance that includes this Circles functionality may be affected until fixed.
Risk and Exploitability
The CVSS score of 6.2 indicates moderate severity. The EPSS score of less than 1% and the absence from the CISA KEV catalog suggest a low probability of widespread exploitation at present, but the bug is accessible to anyone with network access to the public Nextcloud endpoints. An unauthenticated attacker can map the internal network topology by probing reachability of local addresses from the server, potentially aiding later attacks. The flaw requires no privileged client interaction and bypasses core SSRF protections, making it a straightforward blind SSRF vector.
OpenCVE Enrichment