CVE-2026-41237: Froxlor has an incomplete fix for CVE-2026-30932
(updated )
The LOC record regex uses \s+ which matches newlines (allowing embedded newlines to pass), TLSA matchingType=0 has no upper bound on hex data length, and all validators return raw input without zone-file escaping.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-41237 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →