← All Advisories

CVE-2026-90937

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-90937

Key Details

CVECVE-2026-90937
CVSS Score / Version9.9 (Critical) / CVSS v3.1
Updated2026-09-23
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
CVSS Proseattack vector is network; attack complexity is low; privileges required is low; user interaction is none; scope is changed; confidentiality impact is high; integrity impact is high; availability impact is low.
Affected productsfroxlor froxlor
Classified asCWE-93 (Improper Neutralization of CRLF Sequences ('CRLF Injection'))

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
froxlorfroxlor
SubsystemsGeneral OT
SectorsMultiple

What to Know

froxlor versions before 2.2.5 fail to validate newline characters in subdomain redirect URLs, allowing authenticated customers to inject arbitrary nginx or Apache configuration directives. Attackers can supply URLs containing literal newlines that are written verbatim into vhost config files during cron rebuild, enabling web server configuration corruption, denial of service, or hijacking of HTTP responses across hosted domains. (NVD)

What to Do

Monitor froxlor's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-90937
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-90937