CVE-2026-41234

HIGH

Froxlor: BIND Zone File Injection via TXT Record Content

Title source: cna
STIX 2.1

Description

Froxlor is open source server administration software. Prior to version 2.3.7, the `DomainZones.add` API endpoint does not sanitize newline characters in TXT record content. An authenticated customer with DNS editing enabled can inject newlines into TXT record values, which break out of the record line in the generated BIND zone file. This enables injection of arbitrary BIND directives (`$INCLUDE`, `$GENERATE`) and arbitrary DNS records (A, MX, CNAME) into the zone file written to disk by the DNS rebuild cron. This is an incomplete fix for CVE-2026-30932 (GHSA-x6w6-2xwp-3jh6), which patched the same newline injection for LOC, RP, SSHFP, and TLSA record types but did not patch TXT records. Version 2.3.7 contains an updated patch.

References (3)

Core 3
Core References
X_Refsource_Misc x_refsource_misc
https://github.com/advisories/GHSA-x6w6-2xwp-3jh6
X_Refsource_Misc x_refsource_misc
https://github.com/froxlor/froxlor/releases/tag/2.3.7

Scores

CVSS v3 7.6
EPSS 0.0046
EPSS Percentile 35.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-74
Status published
Products (2)
froxlor/froxlor 0 - 2.3.7Packagist
froxlor/froxlor < 2.3.7
Published Jun 04, 2026
Tracked Since Jun 05, 2026