CVE-2026-100717

LOWCVSS 8.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

froxlor is a server administration panel. In versions 2.3.10 and earlier, Validate::validateUrl rejects carriage return and line feed characters only in the path, query and fragment components returned by parse_url, and never inspects the userinfo (user:pass@) components. This is an incomplete fix for GHSA-c3p2. An authenticated low-privilege customer with subdomain-create rights (no admin or change_serversettings privilege required) can supply a subdomain redirect URL that carries a CR/LF payload in the userinfo portion (e.g. http://user%0areturn 200 "pwned";%[email protected]/). The value passes validation, survives IDNA encoding, and is written verbatim into the generated nginx or Apache vhost configuration, allowing the attacker to break out of the emitted directive and inject arbitrary web-server configuration lines. froxlor regenerates and reloads the web-server configuration as root, so the injected directives take effect server-wide and can hijack responses or read local files. The issue is fixed in version 2.3.12.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-93

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked 1d ago at 1 mentions (2026-09-26); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-09-26: 1Mentions · 2026-09-27: 109-2609-27
Referenced assets2 URLs
Full discourse2 posts
  • ThreatAft@ThreatAft

    🔐🚨 FROXLOR — 3 CVEs, 2 × CVSS 9.9 • CVE-2026-100716 — Symlink path traversal → chown /etc • CVE-2026-100717 — CRLF injection → nginx/Apache config → https://threataft.com/articles/froxlor-mass-disclosure-cve-2026-100716-100717-100715 #Froxlor #CVE #PathTraversal #PatchNow #CyberSecurity #ThreatIntel

    0000037
    44 followersView on X
  • CVE@CVEnew

    CVE-2026-100717 froxlor is a server administration panel. In versions 2.3.10 and earlier, Validate::validateUrl rejects carriage return and line feed characters only in the path, q… https://www.cve.org/CVERecord?id=CVE-2026-100717

    00000810
    58.1K followersView on X

Explore more