CVE-2026-100717 Overview
CVE-2026-100717 is a carriage return/line feed (CRLF) injection vulnerability in Froxlor, an open-source server administration panel. Versions 2.3.10 and earlier contain an incomplete fix for GHSA-c3p2 in the Validate::validateUrl function. The validator strips CR/LF characters from URL path, query, and fragment components but does not inspect the userinfo portion. An authenticated low-privilege customer with subdomain-create rights can inject arbitrary nginx or Apache directives into the generated vhost configuration. Froxlor reloads the web-server configuration as root, so injected directives take effect server-wide. The issue is fixed in version 2.3.12.
Critical Impact
An authenticated low-privilege customer can inject arbitrary web-server directives executed as root, hijacking HTTP responses or exposing local files across the entire server.
Affected Products
- Froxlor versions 2.3.10 and earlier
- Froxlor-managed nginx vhost configurations
- Froxlor-managed Apache vhost configurations
Discovery Timeline
- 2026-09-26 - CVE-2026-100717 published to the National Vulnerability Database
- 2026-09-30 - Last updated in NVD database
Technical Details for CVE-2026-100717
Vulnerability Analysis
Froxlor allows customers to configure subdomain redirects by supplying a target URL. The Validate::validateUrl function parses the URL with parse_url and then rejects CR (%0a) and LF (%0d) characters appearing in the path, query, and fragment components. The userinfo component, which carries optional user:pass@ credentials, is never inspected for control characters.
An attacker supplies a redirect URL such as http://user%0areturn 200 "pwned";%0a@evil.com/. The URL passes validation, survives IDNA encoding, and is written verbatim into the generated vhost file. The embedded newline terminates the current directive and introduces attacker-controlled configuration lines. Froxlor subsequently regenerates and reloads nginx or Apache as root, applying the injected configuration server-wide.
This is classified as improper neutralization of CRLF sequences [CWE-93]. Exploitation requires only a standard customer account with subdomain-create privileges. No admin role or change_serversettings privilege is required.
Root Cause
The validateUrl routine applies CR/LF filtering selectively. By checking only path, query, and fragment output from parse_url, the function leaves the user and pass subcomponents unvalidated. Any encoded newline inside the userinfo portion survives sanitization and is reflected into the final vhost template.
Attack Vector
The attack requires authenticated access with customer-level subdomain management rights. The attacker submits a redirect URL containing URL-encoded CR/LF sequences inside the userinfo portion. Froxlor stores the value, templates it into the next vhost rebuild, and reloads the web server. Injected directives can rewrite responses, serve arbitrary content, proxy to attacker hosts, or disclose files readable by the web server process.
See the Froxlor GitHub Security Advisory and the VulnCheck Advisory for Froxlor for additional technical detail.
Detection Methods for CVE-2026-100717
Indicators of Compromise
- Unexpected directives in nginx or Apache vhost files under Froxlor's generated configuration directory, particularly directives that do not match standard Froxlor templates.
- Subdomain redirect records in the Froxlor database containing %0a, %0d, or raw newline bytes within the URL userinfo segment.
- Web-server reload events immediately following customer subdomain configuration changes from low-privilege accounts.
Detection Strategies
- Audit the Froxlor panel_domainredirects and related subdomain tables for stored URLs containing encoded CR/LF sequences in the user or password segment.
- Diff generated vhost files against expected Froxlor template output to identify directives that fall outside the standard structure.
- Review Froxlor action logs for subdomain creation or modification events submitted by non-administrator customer accounts.
Monitoring Recommendations
- Monitor file integrity on /etc/nginx/sites-enabled/, /etc/apache2/sites-enabled/, and equivalent Froxlor-managed vhost directories.
- Alert on root-level reloads of nginx or Apache triggered by Froxlor cron jobs following customer activity.
- Capture HTTP response anomalies such as unexpected return directives, modified content-length values, or hijacked status codes.
How to Mitigate CVE-2026-100717
Immediate Actions Required
- Upgrade Froxlor to version 2.3.12 or later immediately on all managed servers.
- Audit existing subdomain redirect records for malicious payloads before regenerating vhost configurations.
- Review all vhost files generated since version 2.3.10 was deployed and remove any injected directives.
- Rotate any secrets or credentials that may have been exposed through hijacked HTTP responses or local file reads.
Patch Information
The Froxlor maintainers released version 2.3.12, which extends CR/LF validation to the userinfo components returned by parse_url. Refer to the Froxlor GitHub Security Advisory GHSA-gxx3-hwjc-h2gp for the authoritative fix reference.
Workarounds
- Temporarily revoke subdomain-create permissions from customer accounts until the upgrade to 2.3.12 is applied.
- Add a web application firewall rule that blocks %0a and %0d sequences in form fields used for subdomain redirect targets.
- Manually review and sanitize any customer-submitted redirect URLs before Froxlor regenerates the next vhost configuration.
# Verify installed Froxlor version and upgrade
dpkg -l | grep froxlor
# Or via composer-based installations
cd /var/www/froxlor && git fetch --tags && git checkout 2.3.12
# Scan existing vhost files for injected directives
grep -RnE $'\r|\n{2,}' /etc/nginx/sites-enabled/ /etc/apache2/sites-enabled/
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
