CRITICAL 9.4 NVD

CVE-2026-90937

froxlor versions before 2.2.5 fail to validate newline characters in subdomain redirect URLs, allowing authenticated customers to inject arbitrary nginx or Apac

froxlor versions before 2.2.5 fail to validate newline characters in subdomain redirect URLs, allowing authenticated customers to inject arbitrary nginx or Apache configuration directives. Attackers can supply URLs containing literal newlines that are written verbatim into vhost config files during cron rebuild, enabling web server configuration corruption, denial of service, or hijacking of HTTP responses across hosted domains.

References

Published: 2026-09-14 · Source: NVD · Feed updated: 2026-09-15
This critical severity vulnerability with a CVSS score of 9.4 was published on 2026-09-14 via NVD.

Risk Timeline

CVE Disclosed2026-09-14 · 0 days ago

Remediation Resources

vulnfeed aggregates 10822 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.