CVE-2026-41237

HIGH

Froxlor <2.3.7 DNS Record Validation - Zone File Injection

Title source: manual
STIX 2.1

Description

Froxlor is open source server administration software. In version 2.3.6 and earlier, the LOC record regex uses `\s+` which matches newlines (allowing embedded newlines to pass), TLSA `matchingType=0` has no upper bound on hex data length, and all validators return raw input without zone-file escaping. Version 2.3.7 contains an updated patch.

References (3)

Core 3

Scores

CVSS v4 8.6
EPSS 0.0047
EPSS Percentile 36.6%
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-74
Status published
Products (2)
froxlor/froxlor 0 - 2.3.7Packagist
froxlor/froxlor < 2.3.7
Published Jun 04, 2026
Tracked Since Jun 05, 2026