<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 09 Oct 2026 18:26:35 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-324687</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-324687</link>
      <description>EUVD-2026-324687</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-324687</guid>
    </item>
    <item>
      <title>fkie_cve-2026-41234</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-41234</link>
      <description>&lt;p&gt;Froxlor is open source server administration software. Prior to version 2.3.7, the `DomainZones.add` API endpoint does not sanitize newline characters in TXT record content. An authenticated customer with DNS editing enabled can inject newlines into TXT record values, which break out of the record line in the generated BIND zone file. This enables injection of arbitrary BIND directives (`$INCLUDE`, `$GENERATE`) and arbitrary DNS records (A, MX, CNAME) into the zone file written to disk by the DNS rebuild cron. This is an incomplete fix for CVE-2026-30932 (GHSA-x6w6-2xwp-3jh6), which patched the same newline injection for LOC, RP, SSHFP, and TLSA record types but did not patch TXT records. Version 2.3.7 contains an updated patch.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Froxlor is open source server administration software. Prior to version 2.3.7, the `DomainZones.add` API endpoint does not sanitize newline characters in TXT record content. An authenticated customer with DNS editing enabled can inject newlines into TXT record values, which break out of the record line in the generated BIND zone file. This enables injection of arbitrary BIND directives (`$INCLUDE`, `$GENERATE`) and arbitrary DNS records (A, MX, CNAME) into the zone file written to disk by the DNS rebuild cron. This is an incomplete fix for CVE-2026-30932 (GHSA-x6w6-2xwp-3jh6), which patched the same newline injection for LOC, RP, SSHFP, and TLSA record types but did not patch TXT records. Version 2.3.7 contains an updated patch.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-41234</guid>
    </item>
    <item>
      <title>GHSA-37m5-m4q3-fc6x — Froxlor: BIND Zone File Injection via TXT Record Content</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-37m5-m4q3-fc6x</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: froxlor/froxlor&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The `DomainZones.add` API endpoint does not sanitize newline characters in TXT record content. An authenticated customer with DNS editing enabled can inject newlines into TXT record values, which break out of the record line in the generated BIND zone file. This enables injection of arbitrary BIND directives (`$INCLUDE`, `$GENERATE`) and arbitrary DNS records (A, MX, CNAME) into the zone file written to disk by the DNS rebuild cron.&lt;/p&gt;
&lt;p&gt;This is an incomplete fix for CVE-2026-30932 (GHSA-x6w6-2xwp-3jh6), which patched the same newline injection for LOC, RP, SSHFP, and TLSA record types but did not patch TXT records.&lt;/p&gt;
&lt;p&gt;## Affected Code&lt;/p&gt;
&lt;p&gt;`lib/Froxlor/Api/Commands/DomainZones.php`, lines 306-308:&lt;/p&gt;
&lt;p&gt;```php
} elseif ($type == &amp;#39;TXT&amp;#39; &amp;amp;&amp;amp; !empty($content)) {
    // check that TXT content is enclosed in &amp;#34; &amp;#34;
    $content = Dns::encloseTXTContent($content);
}
```&lt;/p&gt;
&lt;p&gt;`Dns::encloseTXTContent()` (`lib/Froxlor/Dns/Dns.php:571-592`) only adds or removes surrounding quote characters. It does not strip newlines, carriage returns, or any BIND zone metacharacters.&lt;/p&gt;
&lt;p&gt;Line 148 of `DomainZones.php` still contains:
```php
// TODO regex validate content for invalid characters
```&lt;/p&gt;
&lt;p&gt;The content flows to the zone file via `DnsEntry::__toString()` (`lib/Froxlor/Dns/DnsEntry.php:83`), which concatenates `$this-&amp;gt;content` directly into the zone line followed by `PHP_EOL`. Embedded newlines in the content produce additional lines in the zone file output.&lt;/p&gt;
&lt;p&gt;### Comparison with CVE-2026-30932 fix&lt;/p&gt;
&lt;p&gt;The v2.3.5…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: froxlor/froxlor&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The `DomainZones.add` API endpoint does not sanitize newline characters in TXT record content. An authenticated customer with DNS editing enabled can inject newlines into TXT record values, which break out of the record line in the generated BIND zone file. This enables injection of arbitrary BIND directives (`$INCLUDE`, `$GENERATE`) and arbitrary DNS records (A, MX, CNAME) into the zone file written to disk by the DNS rebuild cron.&lt;/p&gt;
&lt;p&gt;This is an incomplete fix for CVE-2026-30932 (GHSA-x6w6-2xwp-3jh6), which patched the same newline injection for LOC, RP, SSHFP, and TLSA record types but did not patch TXT records.&lt;/p&gt;
&lt;p&gt;## Affected Code&lt;/p&gt;
&lt;p&gt;`lib/Froxlor/Api/Commands/DomainZones.php`, lines 306-308:&lt;/p&gt;
&lt;p&gt;```php
} elseif ($type == &amp;#39;TXT&amp;#39; &amp;amp;&amp;amp; !empty($content)) {
    // check that TXT content is enclosed in &amp;#34; &amp;#34;
    $content = Dns::encloseTXTContent($content);
}
```&lt;/p&gt;
&lt;p&gt;`Dns::encloseTXTContent()` (`lib/Froxlor/Dns/Dns.php:571-592`) only adds or removes surrounding quote characters. It does not strip newlines, carriage returns, or any BIND zone metacharacters.&lt;/p&gt;
&lt;p&gt;Line 148 of `DomainZones.php` still contains:
```php
// TODO regex validate content for invalid characters
```&lt;/p&gt;
&lt;p&gt;The content flows to the zone file via `DnsEntry::__toString()` (`lib/Froxlor/Dns/DnsEntry.php:83`), which concatenates `$this-&amp;gt;content` directly into the zone line followed by `PHP_EOL`. Embedded newlines in the content produce additional lines in the zone file output.&lt;/p&gt;
&lt;p&gt;### Comparison with CVE-2026-30932 fix&lt;/p&gt;
&lt;p&gt;The v2.3.5…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-37m5-m4q3-fc6x</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1782 — Froxlor: Schwachstelle ermöglicht Manipulation, Offenlegung und DoS</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1782</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Froxlor ausnutzen, um Daten zu manipulieren, Informationen offenzulegen oder einen Denial of Servcie zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Froxlor ausnutzen, um Daten zu manipulieren, Informationen offenzulegen oder einen Denial of Servcie zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1782</guid>
    </item>
  </channel>
</rss>
