C · SEPTEMBER 2026 · EARLY WARNING

Froxlor Vulnerability CVE-2026-90937: Critical Configuration Injection Risk

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
Severity
CRITICAL
CVSS
9.9
Affected component
froxlor (other)
Affected versions
>= 2.2.4, <= 2.2.4 or >= 2.2.3, <= 2.2.3 or >= 2.2.2, <= 2.2.2 or >= 2.2.1, <= 2.2.1 or >= 2.2.0, <= 2.2.0 or >= 2.2.0-rc3, <= 2.2.0-rc3 or >= 2.2.0-rc2, <= 2.2.0-rc2 or >= 2.2.0-rc1, <= 2.2.0-rc1 or >= 2.1.4, <= 2.1.4 or >= 2.1.3, <= 2.1.3 or >= 2.1.2, <= 2.1.2 or >= 2.1.1, <= 2.1.1 or >= 2.1.0, <= 2.1.0 or >= 2.1.0-rc3, <= 2.1.0-rc3 or >= 2.1.0-rc2, <= 2.1.0-rc2 or >= 2.1.0-rc1, <= 2.1.0-rc1 or >= 2.1.0-beta2, <= 2.1.0-beta2 or >= 2.1.0-beta1, <= 2.1.0-beta1 or >= 2.0.24, <= 2.0.24 or >= 2.0.23, <= 2.0.23 or >= 2.0.22, <= 2.0.22 or >= 2.0.21, <= 2.0.21 or >= 2.0.20, <= 2.0.20 or >= 2.0.19, <= 2.0.19 or >= 2.0.18, <= 2.0.18 or >= 2.0.17, <= 2.0.17 or >= 2.0.16, <= 2.0.16 or >= 2.0.15, <= 2.0.15 or >= 2.0.14, <= 2.0.14 or >= 2.0.13, <= 2.0.13 or >= 2.0.12, <= 2.0.12 or >= 2.0.11, <= 2.0.11 or >= 2.0.10, <= 2.0.10 or >= 2.0.9, <= 2.0.9 or >= 2.0.8, <= 2.0.8 or >= 2.0.7, <= 2.0.7 or >= 2.0.6, <= 2.0.6 or >= 2.0.5, <= 2.0.5 or >= 2.0.4, <= 2.0.4 or >= 2.0.3, <= 2.0.3 or >= 2.0.2, <= 2.0.2 or >= 2.0.1, <= 2.0.1 or >= 0.10.33, <= 0.10.33 or >= 0.10.32, <= 0.10.32 or >= 0.10.31, <= 0.10.31 or >= 0.10.30, <= 0.10.30 or >= 0.10.29.1, <= 0.10.29.1 or >= 0.10.29, <= 0.10.29 or >= 0.10.28, <= 0.10.28 or >= 0.10.27, <= 0.10.27 or >= 0.10.26, <= 0.10.26 or >= 0.10.25, <= 0.10.25 or >= 0.10.24, <= 0.10.24 or >= 0.10.23.1, <= 0.10.23.1 or >= 0.10.23, <= 0.10.23 or >= 0.10.22, <= 0.10.22 or >= 0.10.21, <= 0.10.21 or >= 0.10.20, <= 0.10.20 or >= 0.10.19, <= 0.10.19 or >= 0.10.18, <= 0.10.18 or >= 0.10.17, <= 0.10.17 or >= 0.10.16, <= 0.10.16 or >= 0.10.15, <= 0.10.15 or >= 0.10.14, <= 0.10.14 or >= 0.10.13, <= 0.10.13 or >= 0.10.12, <= 0.10.12 or >= 0.10.11, <= 0.10.11 or >= 0.10.10, <= 0.10.10 or >= 0.10.9, <= 0.10.9 or >= 0.10.8, <= 0.10.8 or >= 0.10.7, <= 0.10.7 or >= 0.10.6, <= 0.10.6 or >= 0.10.5, <= 0.10.5 or >= 0.10.4, <= 0.10.4 or >= 0.10.3, <= 0.10.3 or >= 0.10.2, <= 0.10.2 or >= 0.10.1, <= 0.10.1 or >= 0.10.0, <= 0.10.0 or >= 0.10.0-rc2, <= 0.10.0-rc2 or >= 0.10.0-rc1, <= 0.10.0-rc1 or >= 0.9.39.5, <= 0.9.39.5 or >= 0.9.39.4, <= 0.9.39.4 or >= 0.9.39.3, <= 0.9.39.3 or >= 0.9.39.2, <= 0.9.39.2 or >= 0.9.39.1, <= 0.9.39.1 or >= 0.9.39, <= 0.9.39 or >= 0.9.38.8, <= 0.9.38.8 or >= 0.9.38.7, <= 0.9.38.7 or >= 0.9.38.6, <= 0.9.38.6 or >= 0.9.38.5, <= 0.9.38.5 or >= 0.9.38.4, <= 0.9.38.4 or >= 0.9.38.3, <= 0.9.38.3 or >= 0.9.38.2, <= 0.9.38.2 or >= 0.9.38.1, <= 0.9.38.1 or >= 0.9.38, <= 0.9.38 or >= 0.9.38-rc2, <= 0.9.38-rc2 or >= 0.9.38-rc1, <= 0.9.38-rc1 or >= 0.9.37, <= 0.9.37 or >= 0.9.37-rc1, <= 0.9.37-rc1 or >= 0.9.36, <= 0.9.36 or >= 0.9.35.1, <= 0.9.35.1 or >= 0.9.35, <= 0.9.35 or >= 0.9.35-rc1, <= 0.9.35-rc1 or >= 0.9.34.2, <= 0.9.34.2 or >= 0.9.34.1, <= 0.9.34.1 or >= 0.9.33-rc3, <= 0.9.33-rc3 or >= 0.9.33-rc2, <= 0.9.33-rc2 or >= 0.9.33-rc1, <= 0.9.33-rc1 or >= 0.9.32, <= 0.9.32 or >= 0.9.32-rc2, <= 0.9.32-rc2 or >= 0.9.32-rc1, <= 0.9.32-rc1 or >= 0.9.31-rc1, <= 0.9.31-rc1 or >= 0.9.30, <= 0.9.30 or >= 0.9.30-rc1, <= 0.9.30-rc1 or >= 0.9.29, <= 0.9.29 or >= 0.9.29-rc1, <= 0.9.29-rc1 or >= 0.9.28.1, <= 0.9.28.1 or >= 0.9.28, <= 0.9.28 or >= 0.9.28-rc1, <= 0.9.28-rc1 or >= 0.9.27, <= 0.9.27 or >= 0.9.27-rc1, <= 0.9.27-rc1 or >= 0.9.26, <= 0.9.26 or >= 0.9.26-rc1, <= 0.9.26-rc1 or >= 0.9.25, <= 0.9.25 or >= 0.9.25-rc1, <= 0.9.25-rc1 or >= 0.9.24, <= 0.9.24 or >= 0.9.24-rc1, <= 0.9.24-rc1 or >= 0.9.23, <= 0.9.23 or >= 0.9.23-rc1, <= 0.9.23-rc1 or >= 0.9.22, <= 0.9.22 or >= 0.9.22-rc1, <= 0.9.22-rc1 or >= 0.9.21, <= 0.9.21 or >= 0.9.20.1, <= 0.9.20.1 or >= 0.9.20, <= 0.9.20 or >= 0.9.19, <= 0.9.19 or >= 0.9.18.1, <= 0.9.18.1 or >= 0.9.18, <= 0.9.18
Patched version
2.2.5
CVE-2026-90937

Froxlor versions before 2.2.5 reportedly contain a critical vulnerability that allows authenticated customers to inject arbitrary nginx or Apache configuration directives.

What happened

Froxlor versions before 2.2.5 fail to validate newline characters in subdomain redirect URLs. This allows authenticated customers to inject arbitrary nginx or Apache configuration directives. Attackers can supply URLs containing literal newlines that are written verbatim into vhost config files during cron rebuild. This enables web server configuration corruption, denial of service, or hijacking of HTTP responses across hosted domains.

The vulnerability is tracked as CVE-2026-90937 with a CVSS score of 9.9. It was first flagged on 2026-09-14T13:19:32.277000+00:00. There are no reports of this vulnerability being exploited in the wild at this time.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If froxlor is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

You are affected if you are running any Froxlor version before 2.2.5.

What should I do right now?

Upgrade to Froxlor version 2.2.5 or later immediately.

Has this been exploited in the wild?

There are no reports of this vulnerability being exploited in the wild at this time.

Where can I get more information?

Consult the primary sources provided for the most up-to-date information.

Sources

Join the 0Day waitlist →

← Back to all threats