<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-09T19:25:12.900523+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-324687</id>
    <title>EUVD-2026-324687</title>
    <updated>2026-10-09T19:25:12.904710+00:00</updated>
    <content>EUVD-2026-324687</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-324687"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-41234</id>
    <title>fkie_cve-2026-41234</title>
    <updated>2026-10-09T19:25:12.904743+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Froxlor is open source server administration software. Prior to version 2.3.7, the `DomainZones.add` API endpoint does not sanitize newline characters in TXT record content. An authenticated customer with DNS editing enabled can inject newlines into TXT record values, which break out of the record line in the generated BIND zone file. This enables injection of arbitrary BIND directives (`$INCLUDE`, `$GENERATE`) and arbitrary DNS records (A, MX, CNAME) into the zone file written to disk by the DNS rebuild cron. This is an incomplete fix for CVE-2026-30932 (GHSA-x6w6-2xwp-3jh6), which patched the same newline injection for LOC, RP, SSHFP, and TLSA record types but did not patch TXT records. Version 2.3.7 contains an updated patch.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-41234"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-37m5-m4q3-fc6x</id>
    <title>GHSA-37m5-m4q3-fc6x — Froxlor: BIND Zone File Injection via TXT Record Content</title>
    <updated>2026-10-09T19:25:12.904777+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: froxlor/froxlor</p>
<p>## Summary</p>
<p>The `DomainZones.add` API endpoint does not sanitize newline characters in TXT record content. An authenticated customer with DNS editing enabled can inject newlines into TXT record values, which break out of the record line in the generated BIND zone file. This enables injection of arbitrary BIND directives (`$INCLUDE`, `$GENERATE`) and arbitrary DNS records (A, MX, CNAME) into the zone file written to disk by the DNS rebuild cron.</p>
<p>This is an incomplete fix for CVE-2026-30932 (GHSA-x6w6-2xwp-3jh6), which patched the same newline injection for LOC, RP, SSHFP, and TLSA record types but did not patch TXT records.</p>
<p>## Affected Code</p>
<p>`lib/Froxlor/Api/Commands/DomainZones.php`, lines 306-308:</p>
<p>```php
} elseif ($type == 'TXT' &amp;&amp; !empty($content)) {
    // check that TXT content is enclosed in " "
    $content = Dns::encloseTXTContent($content);
}
```</p>
<p>`Dns::encloseTXTContent()` (`lib/Froxlor/Dns/Dns.php:571-592`) only adds or removes surrounding quote characters. It does not strip newlines, carriage returns, or any BIND zone metacharacters.</p>
<p>Line 148 of `DomainZones.php` still contains:
```php
// TODO regex validate content for invalid characters
```</p>
<p>The content flows to the zone file via `DnsEntry::__toString()` (`lib/Froxlor/Dns/DnsEntry.php:83`), which concatenates `$this-&gt;content` directly into the zone line followed by `PHP_EOL`. Embedded newlines in the content produce additional lines in the zone file output.</p>
<p>### Comparison with CVE-2026-30932 fix</p>
<p>The v2.3.5…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-37m5-m4q3-fc6x"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1782</id>
    <title>WID-SEC-W-2026-1782 — Froxlor: Schwachstelle ermöglicht Manipulation, Offenlegung und DoS</title>
    <updated>2026-10-09T19:25:12.904846+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Froxlor ausnutzen, um Daten zu manipulieren, Informationen offenzulegen oder einen Denial of Servcie zu verursachen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1782"/>
  </entry>
</feed>
