Two newly disclosed vulnerabilities affect DNS-related configuration handling in Froxlor and Pi-hole FTL, allowing authenticated low-privilege attackers to inject malicious content through unsanitized newline characters. In Froxlor before 2.3.5, the DomainZones.add API endpoint does not properly validate the content field for several DNS record types, enabling attackers with customer access and DNS enabled to insert additional lines and BIND directives such as $INCLUDE into zone files that are written during the DNS rebuild cron job. The flaw is tracked as CVE-2026-30932 and can lead to unauthorized manipulation of DNS zone configuration data.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
A new CVE, CVE-2026-41230, was published for a Froxlor BIND zone file injection flaw in DomainZones::add() affecting versions prior to 2.3.6. The advisory says unsupported DNS record types can bypass validation and newline characters in record content can be used to inject arbitrary BIND directives; Froxlor 2.3.6 fixes the issue.
A new CVE, CVE-2026-35521, was published for Pi-hole FTL versions 6.0 through before 6.6, describing remote code execution via newline injection in the dhcp.hosts configuration parameter. The issue allows an authenticated attacker to inject arbitrary dnsmasq directives and was mapped to CWE-78 and CWE-93.
A new CVE, CVE-2026-35519, was published for Pi-hole FTL versions 6.0 through before 6.6, describing remote code execution via newline injection in the dns.hostRecord configuration parameter. The flaw allows an authenticated attacker to inject arbitrary dnsmasq directives and was mapped to CWE-78 and CWE-93.
Pi-hole FTL addressed the remote code execution issue caused by arbitrary dnsmasq directive injection through dns.upstreams by releasing version 6.6. The vulnerability was mapped to CWE-78 and CWE-93.
A CVE entry for Pi-hole FTL remote code execution via newline injection in the dns.upstreams configuration parameter was received by security-advisories@github.com. The flaw affects pihole-FTL versions 6.0 through before 6.6 and requires authenticated access.
A new vulnerability, CVE-2026-30932, was publicly disclosed for Froxlor, describing BIND zone file injection via unsanitized DNS record content in the DomainZones API. The issue was assigned CWE-74 and a high-severity CVSS v4.0 rating.
Froxlor patched a vulnerability in the DomainZones.add API endpoint that allowed newline injection into DNS record content and unauthorized manipulation of BIND zone files during DNS rebuilds. The flaw affects versions prior to 2.3.5.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.