CVE-2026-90937: froxlor before 2.2.5 nginx/Apache Configuration Injection via subdomain redirect URL

Published Sep 14, 2026
·
Updated

froxlor versions before 2.2.5 fail to validate newline characters in subdomain redirect URLs, allowing authenticated customers to inject arbitrary nginx or Apache configuration directives. Attackers can supply URLs containing literal newlines that are written verbatim into vhost config files during cron rebuild, enabling web server configuration corruption, denial of service, or hijacking of HTTP responses across hosted domains.

Affected Software

1 affected component
Froxlor Froxlor<2.2.5

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade froxlor to a version that resolves this vulnerability.

    Fixed in 2.2.5
  2. Compensating control

    If upgrading immediately is not possible, prevent untrusted/attacker-controlled values from reaching Froxlor's subdomain redirect URL feature (e.g., restrict who can set redirect URLs and ensure only trusted customers/inputs can be used) to mitigate config injection via newline characters.

Event History

Sep 14, 2026
CVE Published
via MITRE·12:48 PM
Data Sourced
via MITRE·12:48 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An authenticated Froxlor customer can exploit it by providing a subdomain redirect URL containing literal newline characters. No user interaction is required.

2

When does the malicious configuration take effect?

The supplied redirect URL is written into virtual-host configuration files during the cron rebuild process. The resulting injected nginx or Apache directives can affect HTTP responses across hosted domains.

3

Which deployments are affected?

Froxlor versions before 2.2.5 are affected where customers can configure subdomain redirect URLs and the configuration is rebuilt into nginx or Apache virtual-host files.

4

What is the impact of successful exploitation?

An attacker may inject arbitrary nginx or Apache configuration directives, causing web-server configuration corruption, denial of service, or hijacking of HTTP responses across hosted domains.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203