CRITICAL 9.4 NVD
CVE-2026-90937
froxlor versions before 2.2.5 fail to validate newline characters in subdomain redirect URLs, allowing authenticated customers to inject arbitrary nginx or Apac
froxlor versions before 2.2.5 fail to validate newline characters in subdomain redirect URLs, allowing authenticated customers to inject arbitrary nginx or Apache configuration directives. Attackers can supply URLs containing literal newlines that are written verbatim into vhost config files during cron rebuild, enabling web server configuration corruption, denial of service, or hijacking of HTTP responses across hosted domains.
References
- https://github.com/froxlor/froxlor/security/advisories/GHSA-c3p2-mj7v-5mrc
- https://www.vulncheck.com/advisories/froxlor-before-2.2.5-nginx-apache-configuration-injec
This critical severity vulnerability with a CVSS score of 9.4 was published on 2026-09-14 via NVD.
Risk Timeline
CVE Disclosed2026-09-14 · 0 days ago
Remediation Resources
vulnfeed aggregates 10822 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.