---
id: CVE-2026-90937
title: >-
  froxlor versions before 2.2.5 fail to validate newline characters in subdomain
  redirect URLs, allowing authenticated customers to inject arbitrary nginx or
  Apache configuration directives
summary: >-
  froxlor versions before 2.2.5 fail to validate newline characters in subdomain
  redirect URLs, allowing authenticated customers to inject arbitrary nginx or
  Apache configuration directives. Attackers can supply URLs containing literal
  new…
severity: critical
cvss: 9.9
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L'
cwe:
  - CWE-93
vendor: froxlor
product: froxlor
affected:
  - froxlor < 2.2.5
published: '2026-09-14'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T17:17:47.610'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90937'
references:
  - url: 'https://github.com/froxlor/froxlor/security/advisories/GHSA-c3p2-mj7v-5mrc'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/froxlor-before-2.2.5-nginx-apache-configuration-injection-via-subdomain-redirect-url
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
epss: 0.00451
epssPercentile: 0.36579
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-16T15:00:48.474679Z'
ingestedAt: '2026-09-14T15:23:07.430Z'
---

## Overview

froxlor versions before 2.2.5 fail to validate newline characters in subdomain redirect URLs, allowing authenticated customers to inject arbitrary nginx or Apache configuration directives. Attackers can supply URLs containing literal newlines that are written verbatim into vhost config files during cron rebuild, enabling web server configuration corruption, denial of service, or hijacking of HTTP responses across hosted domains.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
