resolved
@jitsi/docker-jitsi-meet: `/colibri-relay-ws/` unsafe nginx regex (OCTO relay configuration)
Bug reported by A3z4km3 was disclosed at August 25, 2026, 2:09 am | Cross-site Scripting (XSS) - Generic
An unsafe nginx regex pattern was discovered in the `/colibri-relay-ws/` location of the @jitsi/docker-jitsi-meet project. The regex `[a-zA-Z0-9-\\._]+` accepted arbitrary domain names and IP addresses for proxy_pass directives, allowing unauthenticated requests to be proxied to attacker-specified destinations. The vulnerable nginx location and associated relay WebSocket proxy configuration have been removed.
resolved
URI scheme validation bypass in ActionText `to_markdown` via user-supplied `` marker tag
Bug reported by offset was disclosed at August 24, 2026, 4:21 pm | Cross-site Scripting (XSS) - Reflected
resolved
Path Traversal in Nextcloud Talk Android Exposes User Credentials and Private Data via FileProvider
Bug reported by Michael Liu was disclosed at August 24, 2026, 1:23 am | Path Traversal
A vulnerability in Nextcloud Talk Android allowed an external Android app to write and retrieve config files by pinging an internal endpoint.

