CVE-2026-100717 is an authenticated CRLF injection vulnerability in Froxlor versions 2.3.10 and earlier. The Validate::validateUrl function rejects carriage-return and line-feed characters in parsed URL path, query, and fragment components, but does not inspect the userinfo component. A low-privileged authenticated customer with permission to create subdomains can embed CR/LF sequences in a subdomain redirect URL userinfo value. The value survives validation and IDNA encoding and is written verbatim into generated nginx or Apache virtual-host configuration. The injected characters can terminate the intended directive and introduce arbitrary web-server configuration directives. Froxlor regenerates and reloads the web-server configuration as root, making the injected directives effective server-wide.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical security vulnerability with a reported CVSS score of 9.9. Public active exploitation has not been confirmed in the notice.
A critical authenticated CRLF-injection vulnerability in Froxlor subdomain redirect URL validation. It allows arbitrary nginx or Apache configuration directive injection when Froxlor regenerates and reloads web-server configuration as root.
An authenticated configuration-injection vulnerability in Froxlor caused by incomplete CR/LF validation of redirect URLs. CR/LF payloads in the URL userinfo component can escape generated nginx or Apache virtual-host directives; because Froxlor regenerates and reloads the configuration as root, injected directives take effect server-wide and may hijack responses or expose local files.
A critical authenticated CRLF injection and web-server configuration injection vulnerability in Froxlor. A low-privilege customer with subdomain-create rights can place CR/LF payloads in the userinfo component of a redirect URL, inject arbitrary nginx or Apache configuration directives during vhost generation, and cause server-wide effects including response hijacking or local-file reading.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.