SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-90937

CRITICAL · CVSS 9.9 Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-14 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

Froxlor versions prior to 2.2.5 are vulnerable to newline injection in subdomain redirect URLs, allowing authenticated users to inject arbitrary configuration directives into Apache or Nginx. This can lead to severe impacts, including web server configuration corruption, denial of service, or HTTP response hijacking. Organizations using Froxlor with Apache or Nginx should prioritize patching to mitigate this critical vulnerability.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-90937
Severity
CRITICAL
CVSS
9.9
EPSS
N/A
Apache Nginx

Original NVD Description

froxlor versions before 2.2.5 fail to validate newline characters in subdomain redirect URLs, allowing authenticated customers to inject arbitrary nginx or Apache configuration directives. Attackers can supply URLs containing literal newlines that are written verbatim into vhost config files during cron rebuild, enabling web server configuration corruption, denial of service, or hijacking of HTTP responses across hosted domains.