<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 10 Oct 2026 03:27:23 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-277339</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-277339</link>
      <description>EUVD-2026-277339</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-277339</guid>
    </item>
    <item>
      <title>fkie_cve-2026-30932</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-30932</link>
      <description>&lt;p&gt;Froxlor is open source server administration software. Prior to version 2.3.5, the DomainZones.add API endpoint (accessible to customers with DNS enabled) does not validate the content field for several DNS record types (LOC, RP, SSHFP, TLSA). An attacker can inject newlines and BIND zone file directives (e.g. $INCLUDE) into the zone file that gets written to disk when the DNS rebuild cron job runs. This issue has been patched in version 2.3.5.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Froxlor is open source server administration software. Prior to version 2.3.5, the DomainZones.add API endpoint (accessible to customers with DNS enabled) does not validate the content field for several DNS record types (LOC, RP, SSHFP, TLSA). An attacker can inject newlines and BIND zone file directives (e.g. $INCLUDE) into the zone file that gets written to disk when the DNS rebuild cron job runs. This issue has been patched in version 2.3.5.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-30932</guid>
    </item>
    <item>
      <title>GHSA-x6w6-2xwp-3jh6 — Froxlor is vulnerable to BIND zone file injection via unsanitized DNS record content in DomainZones API</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-x6w6-2xwp-3jh6</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: froxlor/froxlor&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The `DomainZones.add` API endpoint (accessible to customers with DNS enabled) does not validate the `content` field for several DNS record types (LOC, RP, SSHFP, TLSA). An attacker can inject newlines and BIND zone file directives (e.g. `$INCLUDE`) into the zone file that gets written to disk when the DNS rebuild cron job runs.&lt;/p&gt;
&lt;p&gt;## Affected Code&lt;/p&gt;
&lt;p&gt;`lib/Froxlor/Api/Commands/DomainZones.php`, lines 213-214, 253-254, 290-291, 292-293:&lt;/p&gt;
&lt;p&gt;```php
} elseif ($type == &amp;#39;LOC&amp;#39; &amp;amp;&amp;amp; !empty($content)) {
    $content = $content; // no validation
} ...
} elseif ($type == &amp;#39;RP&amp;#39; &amp;amp;&amp;amp; !empty($content)) {
    $content = $content; // no validation
} ...
} elseif ($type == &amp;#39;SSHFP&amp;#39; &amp;amp;&amp;amp; !empty($content)) {
    $content = $content; // no validation
} elseif ($type == &amp;#39;TLSA&amp;#39; &amp;amp;&amp;amp; !empty($content)) {
    $content = $content; // no validation
}
```&lt;/p&gt;
&lt;p&gt;There is even a TODO comment at line 148 acknowledging this gap:
```php
// TODO regex validate content for invalid characters
```&lt;/p&gt;
&lt;p&gt;The content is then written directly into the BIND zone file via `DnsEntry::__toString()` (line 83 of `lib/Froxlor/Dns/DnsEntry.php`):&lt;/p&gt;
&lt;p&gt;```php
return $this-&amp;gt;record . &amp;#34;\t&amp;#34; . $this-&amp;gt;ttl . &amp;#34;\t&amp;#34; . $this-&amp;gt;class . &amp;#34;\t&amp;#34; . $this-&amp;gt;type . &amp;#34;\t&amp;#34; ... . $_content . PHP_EOL;
```&lt;/p&gt;
&lt;p&gt;And the zone file is written to disk in `lib/Froxlor/Cron/Dns/Bind.php` line 121:&lt;/p&gt;
&lt;p&gt;```php
fwrite($zonefile_handler, $zoneContent . $subzones);
```&lt;/p&gt;
&lt;p&gt;## PoC&lt;/p&gt;
&lt;p&gt;As a customer with DNS management enabled and an API key, add a LOC record with injected BIND directives:&lt;/p&gt;
&lt;p&gt;```…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: froxlor/froxlor&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The `DomainZones.add` API endpoint (accessible to customers with DNS enabled) does not validate the `content` field for several DNS record types (LOC, RP, SSHFP, TLSA). An attacker can inject newlines and BIND zone file directives (e.g. `$INCLUDE`) into the zone file that gets written to disk when the DNS rebuild cron job runs.&lt;/p&gt;
&lt;p&gt;## Affected Code&lt;/p&gt;
&lt;p&gt;`lib/Froxlor/Api/Commands/DomainZones.php`, lines 213-214, 253-254, 290-291, 292-293:&lt;/p&gt;
&lt;p&gt;```php
} elseif ($type == &amp;#39;LOC&amp;#39; &amp;amp;&amp;amp; !empty($content)) {
    $content = $content; // no validation
} ...
} elseif ($type == &amp;#39;RP&amp;#39; &amp;amp;&amp;amp; !empty($content)) {
    $content = $content; // no validation
} ...
} elseif ($type == &amp;#39;SSHFP&amp;#39; &amp;amp;&amp;amp; !empty($content)) {
    $content = $content; // no validation
} elseif ($type == &amp;#39;TLSA&amp;#39; &amp;amp;&amp;amp; !empty($content)) {
    $content = $content; // no validation
}
```&lt;/p&gt;
&lt;p&gt;There is even a TODO comment at line 148 acknowledging this gap:
```php
// TODO regex validate content for invalid characters
```&lt;/p&gt;
&lt;p&gt;The content is then written directly into the BIND zone file via `DnsEntry::__toString()` (line 83 of `lib/Froxlor/Dns/DnsEntry.php`):&lt;/p&gt;
&lt;p&gt;```php
return $this-&amp;gt;record . &amp;#34;\t&amp;#34; . $this-&amp;gt;ttl . &amp;#34;\t&amp;#34; . $this-&amp;gt;class . &amp;#34;\t&amp;#34; . $this-&amp;gt;type . &amp;#34;\t&amp;#34; ... . $_content . PHP_EOL;
```&lt;/p&gt;
&lt;p&gt;And the zone file is written to disk in `lib/Froxlor/Cron/Dns/Bind.php` line 121:&lt;/p&gt;
&lt;p&gt;```php
fwrite($zonefile_handler, $zoneContent . $subzones);
```&lt;/p&gt;
&lt;p&gt;## PoC&lt;/p&gt;
&lt;p&gt;As a customer with DNS management enabled and an API key, add a LOC record with injected BIND directives:&lt;/p&gt;
&lt;p&gt;```…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-x6w6-2xwp-3jh6</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0834 — Froxlor: Schwachstelle ermöglicht Manipulation von Dateien und Offenlegung von Informationen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0834</link>
      <description>&lt;p&gt;Ein Angreifer kann eine Schwachstelle in Froxlor ausnutzen, um Dateien zu manipulieren, und um Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann eine Schwachstelle in Froxlor ausnutzen, um Dateien zu manipulieren, und um Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0834</guid>
    </item>
  </channel>
</rss>
