CRITICAL 9.9 CVE-2026-90937 Published 14 Sept 2026

froxlor Subdomain Redirect URL Injection

Worried this affects one of your servers?

froxlor versions before 2.2.5 fail to validate newline characters in subdomain redirect URLs.

Authenticated customers can inject arbitrary nginx or Apache configuration directives, leading to web server configuration corruption, denial of service, or response hijacking across hosted domains.

Reference: CVE-2026-90937 on NVD

← Back to Security News