Froxlor is open source server administration software. In version 2.3.6 and earlier, the LOC record regex uses `\s+` which matches newlines (allowing embedded newlines to pass), TLSA `matchingType=0` has no upper bound on hex data length, and all validators return raw input without zone-file escaping. Version 2.3.7 contains an updated patch.
CVSS
No CVSS.
References
Configurations
No configuration.
History
05 Jun 2026, 20:17
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/froxlor/froxlor/security/advisories/GHSA-j6fm-9rfm-j5hx - |
04 Jun 2026, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-04 19:16
Updated : 2026-06-05 20:17
NVD link : CVE-2026-41237
Mitre link : CVE-2026-41237
CVE.ORG link : CVE-2026-41237
JSON object : View
Products Affected
No product.
CWE
CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
