Skip to content

LibreNMS

v26.5.0 Security

This release includes 6 security fixes for security teams reviewing exposed deployments.

Published 16d Monitoring & Metrics
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 6 known CVEs

Topics

laravel librenms monitoring network php rrd
+1 more
snmp

Affected surfaces

auth rbac

Summary

AI summary

Remove default FortiOS mapping for Oxidized config, change APP_TRUSTED_PROXIES default to 127.0.0.1.

Full changelog

26.5.0

(2026-05-18)

A big thank you to the following 27 contributors this last month:

Thanks to maintainers and others that helped with pull requests this month:

Feature

Breaking Change

  • Remove default fortigate -> fortios match for Oxidized config (#19598) - casdr
  • Cleanup dbSyncRelationship and dbDelete (#19583) - mpikzink
  • Change default APP_TRUSTED_PROXIES to 127.0.0.1 (#19537) - murrant

Security

Device

Webui

Graphs

  • Prevent graph title from being cropped off on both sides (#19589) - murrant

Snmp Traps

Api

Settings

  • Interface parsing docs+settings improvements (#19633) - murrant

Discovery

  • Updated tpdin sensors skipping 0 values (#19507) - laf
  • Add FDB table support for Nokia TiMOS devices (#18713) - peelman

Bug

  • Fixed MapQuest API url (#19671) - szastan
  • Remove dead scopeLimit on Notification model (breaks daily.sh under Laravel 11) (#19669) - swaymel
  • Fix double-encoded builder/extra in alert rule legacy API (#19666) - Starson323
  • Fix graph time picker redirect 404 (#19648) - HaradaKumiko
  • Fixes Xdsl.php when the SNMP response data in an unexpected format (#19641) - sherlvoodi-create
  • Fix link to port on Inventory page (#19597) - laf
  • Added more defaults to OSPFv3 area fields missing from Arista (#19588) - laf
  • Fix logic for dev commands (#19586) - mpikzink
  • Fix SSL Certificate menu hiding on lower sized screen res (#19571) - laf
  • Mistyped variable name breaking custom OID (#19569) - JHarmonPMU
  • Handle GBK-encoded interface names and descriptions in ports polling (#19528) - Yish1
  • Zynos/Zyxel fix port ifName between 50 and 63 (#19341) - Yanonix

Refactor

Cleanup

Translation

Misc

  • Fix uninitialized variables in smokeping graph templates (#19599) - bdg-robert
  • Add check_dnssec_delegation override (#19591) - 49phil
  • Fall back to IEEE 802.3ad LAG-MIB when ifStackTable is missing (#19574) - shward
  • Fix BGP peer device links incorrect with reused IP address space (#19394) - Starson323

Dependencies

Breaking Changes

  • Removed default fortigate -> fortios match for Oxidized config
  • Changed default APP_TRUSTED_PROXIES from unspecified to 127.0.0.1

Security Fixes

  • Composer wrapper escape args — mitigates command injection
  • Fix netmap XSS
  • Various XSS fixes
  • Fix legacy page title XSS
  • Fix XSS in edituser
  • Fix Device Type Widget access

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track LibreNMS

Get notified when new releases ship.

Sign up free

About LibreNMS

Community-based GPL-licensed network monitoring system

All releases →

Beta — feedback welcome: [email protected]