External risk intelligence

Froxlor Subdomain Redirect URL Injection allows Nginx Apache Configuration Manipulation.

CVE advisorySeverity: CRITICAL (CVSS 9.4)

CVE-2026-90937

Froxlor is a server management and hosting control panel designed to be accessed via the internet for administrative tasks. Because it is a web-based management platform commonly deployed to control public-facing web services, the authenticated interface is inherently exposed to the internet.

Denial of Service

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability in froxlor allows authenticated users to inject commands that could corrupt web server configurations. This could lead to denial of service or the hijacking of responses for hosted domains.

  • Subdomain redirects can corrupt web server settings.
  • This impacts web services and hosted domain integrity.
  • Confirm relevance and exposure for hosted domains.

Attack Path

How an attacker could exploit the issue

An attacker with authenticated customer access can inject malicious commands into subdomain redirect URLs. This occurs because the system fails to properly validate newline characters, allowing these commands to be written directly into server configuration files during a routine update. If successful, this could lead to the corruption of web server settings, denial of service, or the hijacking of responses for websites hosted on the server.

  • Authenticated customer access is required.
  • Malicious redirect URLs with newlines trigger the vulnerability.
  • Web server configuration corruption and hijacking.

Live Threat

Current exploitation, exposure, and threat context

Authenticated customers could inject arbitrary web server configuration directives when redirect URLs are processed, potentially leading to web server corruption, denial of service, or response hijacking.

  • Risk to web server configuration.
  • Injection via subdomain redirect URLs.
  • Service disruption or response hijacking.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in froxlor impacts authenticated customers who can manipulate subdomain redirect URLs. Platform or infrastructure teams responsible for managing froxlor instances are likely to lead the response, in coordination with security teams to assess exposure. The first practical step involves identifying all froxlor installations, determining their reachability and business criticality, and locating the accountable owner for each instance to plan targeted remediation.

  • Identify froxlor instances and accountable owners.
  • Verify customer-provided redirect URLs for newlines.
  • Plan and coordinate targeted remediation or mitigation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is froxlor and how is it used?

Froxlor is an open-source server management and hosting control panel. Administrators and their customers use it via a web interface to configure web servers, manage domains, and handle email or FTP accounts. It simplifies the complex task of maintaining web services, allowing users to define settings for Apache or Nginx through a centralized dashboard.

How does CVE-2026-90937 work?

This vulnerability is an Improper Neutralization of CRLF Sequences, classified as CWE-93. It occurs because the software fails to filter newline characters in subdomain redirect URLs. When these malicious strings are saved, they break out of the intended data fields and are written directly into the web server's configuration files during the next automated update, effectively allowing the injection of unauthorized commands.

What triggers this configuration injection?

An attacker needs authenticated access as a customer to manipulate subdomain redirect settings. The vulnerability is triggered specifically when a crafted URL containing literal newline characters is submitted. Importantly, simply visiting the site or browsing public pages without an active customer account does not trigger this flaw; it requires the ability to save redirect URL configurations within the control panel.

Is my froxlor instance at risk?

If you host a froxlor instance, it is likely relevant to your security posture. According to Halo Surface Signal, because froxlor is a web-based control panel designed for managing public-facing services, its interface is typically exposed to the internet. If you allow customers to log in and manage their own subdomain redirects, your server configuration is potentially vulnerable to any authenticated user who chooses to exploit this flaw.

What should I do to secure my system?

The primary response is to update froxlor to version 2.2.5 or later, which includes the necessary input validation fixes. Before applying updates, identify all active froxlor installations in your environment and confirm who manages them. If you cannot update immediately, audit existing subdomain redirect configurations for suspicious newline characters that may have already been introduced to your web server files.

References