CVE-2026-90937
froxlor versions before 2.2.5 fail to validate newline characters in subdomain redirect URLs, allowing authenticated customers to inject arbitrary nginx or Apache configuration directives. Attackers can supply URLs containing literal newlines that are written verbatim into vhost config files during cron rebuild, enabling web server configuration corruption, denial of service, or hijacking of HTTP responses across hosted domains.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.9
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L
- EPSS probability
- 0.26%
- CWE
- CWE-93
- Published
- 2026-09-14
- Last modified
- 2026-09-16
Affected products
- froxlor froxlor
- froxlor froxlor
Weakness type
Related vulnerabilities
- CVE-2021-39172 — New line injection during configuration edition
- CVE-2024-51501 — CRLF injection in Refit's [Header], [HeaderCollection] and [Authorize] attributes
- CVE-2024-32986 — Arbitrary code execution due to improper sanitization of web app properties in PWAsForFirefox
- CVE-2025-40671 — SQL injection vulnerability in AES Multimedia's Gestnet
- CVE-2026-29046 — TinyWeb: HTTP Header Control Character Injection into CGI Environment
- CVE-2025-8715 — PostgreSQL pg_dump newline in object name executes arbitrary code in psql client and in restore target server
- CVE-2022-0666 — CRLF Injection leads to Stack Trace Exposure due to lack of filtering at https://demo.microweber.org/ in microweber/microweber
- CVE-2026-23953 — Incus container environment configuration newline injection