CVE-2026-41237
Froxlor is open source server administration software. In version 2.3.6 and earlier, the LOC record regex uses `\s+` which matches newlines (allowing embedded newlines to pass), TLSA `matchingType=0` has no upper bound on hex data length, and all validators return raw input without zone-file escaping. Version 2.3.7 contains an updated patch.
- Fix
- Available
- CVSS 4.0
- 8.6 HIGH
- EPSS
- 0.3% (19th percentile)
- Weakness
- CWE-74
- NVD status
- Deferred
- Published
- 2026-06-04
CVE-2026-41237 at NVD
No indexed exploits for CVE-2026-41237 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2026-41237 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.