CVE-2026-41237

Froxlor is open source server administration software. In version 2.3.6 and earlier, the LOC record regex uses `\s+` which matches newlines (allowing embedded newlines to pass), TLSA `matchingType=0` has no upper bound on hex data length, and all validators return raw input without zone-file escaping. Version 2.3.7 contains an updated patch.
CVSS

No CVSS.

Configurations

No configuration.

History

22 Jul 2026, 20:10

Type Values Removed Values Added
Summary
  • (es) Froxlor es un software de administración de servidores de código abierto. En la versión 2.3.6 y anteriores, la expresión regular del registro LOC utiliza '\s+' que coincide con saltos de línea (permitiendo que los saltos de línea incrustados pasen), TLSA 'matchingType=0' no tiene un límite superior en la longitud de los datos hexadecimales, y todos los validadores devuelven la entrada sin procesar sin escape de archivo de zona. La versión 2.3.7 contiene un parche actualizado.

05 Jun 2026, 20:17

Type Values Removed Values Added
References () https://github.com/froxlor/froxlor/security/advisories/GHSA-j6fm-9rfm-j5hx - () https://github.com/froxlor/froxlor/security/advisories/GHSA-j6fm-9rfm-j5hx -

04 Jun 2026, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-04 19:16

Updated : 2026-07-22 20:10


NVD link : CVE-2026-41237

Mitre link : CVE-2026-41237

CVE.ORG link : CVE-2026-41237


JSON object : View

Products Affected

No product.

CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')