CVE-2026-41237

Froxlor is open source server administration software. In version 2.3.6 and earlier, the LOC record regex uses `\s+` which matches newlines (allowing embedded newlines to pass), TLSA `matchingType=0` has no upper bound on hex data length, and all validators return raw input without zone-file escaping. Version 2.3.7 contains an updated patch.
CVSS

No CVSS.

Configurations

No configuration.

History

05 Jun 2026, 20:17

Type Values Removed Values Added
References () https://github.com/froxlor/froxlor/security/advisories/GHSA-j6fm-9rfm-j5hx - () https://github.com/froxlor/froxlor/security/advisories/GHSA-j6fm-9rfm-j5hx -

04 Jun 2026, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-04 19:16

Updated : 2026-06-05 20:17


NVD link : CVE-2026-41237

Mitre link : CVE-2026-41237

CVE.ORG link : CVE-2026-41237


JSON object : View

Products Affected

No product.

CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')