Issue Description

By default Nextcloud Mail will not load images in HTML mail. This could be bypassed with // uri.

Affected versions

Nextcloud Mail Application up to 1.10.3


Creating image tag with following syntax <img src=//server/trackingpixel.png> will bypass the image blocking filter.


Vendor notified 17.08.2021
Fix released 15.09.2021

CVE-2021-39220 was issued