CVE-2026-41234
HIGHFroxlor: BIND Zone File Injection via TXT Record Content
Title source: cnaDescription
Froxlor is open source server administration software. Prior to version 2.3.7, the `DomainZones.add` API endpoint does not sanitize newline characters in TXT record content. An authenticated customer with DNS editing enabled can inject newlines into TXT record values, which break out of the record line in the generated BIND zone file. This enables injection of arbitrary BIND directives (`$INCLUDE`, `$GENERATE`) and arbitrary DNS records (A, MX, CNAME) into the zone file written to disk by the DNS rebuild cron. This is an incomplete fix for CVE-2026-30932 (GHSA-x6w6-2xwp-3jh6), which patched the same newline injection for LOC, RP, SSHFP, and TLSA record types but did not patch TXT records. Version 2.3.7 contains an updated patch.
References (3)
Core 3
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/froxlor/froxlor/security/advisories/GHSA-37m5-m4q3-fc6x
X_Refsource_Misc x_refsource_misc
https://github.com/advisories/GHSA-x6w6-2xwp-3jh6
X_Refsource_Misc x_refsource_misc
https://github.com/froxlor/froxlor/releases/tag/2.3.7
Scores
CVSS v3
7.6
EPSS
0.0046
EPSS Percentile
35.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-74
Status
published
Products (2)
froxlor/froxlor
0 - 2.3.7Packagist
froxlor/froxlor
< 2.3.7
Published
Jun 04, 2026
Tracked Since
Jun 05, 2026