Status: UPDATED
| Advisory ID: CVE-2026-90937
Key Details
| CVE | CVE-2026-90937 |
| CVSS Score / Version | 9.9 (Critical) / CVSS v3.1 |
| Updated | 2026-09-23 |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L |
| CVSS Prose | attack vector is network; attack complexity is low; privileges required is low; user interaction is none; scope is changed; confidentiality impact is high; integrity impact is high; availability impact is low. |
| Affected products | froxlor froxlor |
| Classified as | CWE-93 (Improper Neutralization of CRLF Sequences ('CRLF Injection')) |
Affected Products, Subsystems & Sectors
| Subsystems | General OT |
| Sectors | Multiple |
What to Know
froxlor versions before 2.2.5 fail to validate newline characters in subdomain redirect URLs, allowing authenticated customers to inject arbitrary nginx or Apache configuration directives. Attackers can supply URLs containing literal newlines that are written verbatim into vhost config files during cron rebuild, enabling web server configuration corruption, denial of service, or hijacking of HTTP responses across hosted domains. (NVD)
What to Do
Monitor froxlor's web page for any future patch releases.
References