This release includes 6 security fixes for security teams reviewing exposed deployments.
Published 16d
Monitoring & Metrics
✓ No known CVEs patched
This release patches 6 known CVEs
Topics
laravel
librenms
monitoring
network
php
rrd
+1 more
snmp
Affected surfaces
auth
rbac
Summary
AI summaryRemove default FortiOS mapping for Oxidized config, change APP_TRUSTED_PROXIES default to 127.0.0.1.
Full changelog
26.5.0
(2026-05-18)
A big thank you to the following 27 contributors this last month:
- murrant (37)
- laf (17)
- mpikzink (6)
- bdg-robert (5)
- dependabot (4)
- Npeca75 (3)
- craig-nokia (2)
- Starson323 (2)
- redundantredundancy (2)
- szastan (1)
- swaymel (1)
- HaradaKumiko (1)
- sherlvoodi-create (1)
- kivu8 (1)
- opalivan (1)
- matheorism (1)
- casdr (1)
- 49phil (1)
- eskyuu (1)
- shward (1)
- JHarmonPMU (1)
- Palerm0 (1)
- Yish1 (1)
- isolson (1)
- Yanonix (1)
- glennmatth (1)
- peelman (1)
Thanks to maintainers and others that helped with pull requests this month:
- laf (37)
- murrant (25)
- Jellyfrog (3)
- PipoCanaja (3)
- mpikzink (1)
- copilot-pull-request-reviewer (1)
Feature
Breaking Change
- Remove default fortigate -> fortios match for Oxidized config (#19598) - casdr
- Cleanup dbSyncRelationship and dbDelete (#19583) - mpikzink
- Change default APP_TRUSTED_PROXIES to 127.0.0.1 (#19537) - murrant
Security
- Composer wrapper escape args (#19663) - murrant
- Fix netmap xss (#19661) - murrant
- Various XSS fixes (#19660) - murrant
- Fix legacy page title xss (#19659) - murrant
- Fix xss in edituser (#19592) - murrant
- Fix Device Type Widget access (#19568) - murrant
Device
- Added Pool IPs used for FlexBNG devices (#19684) - laf
- Default Nokia TiMOS transceiver channels to 1 when lane count is missing (#19678) - craig-nokia
- Add discovery support for additional AXIS OS device types (#19653) - redundantredundancy
- Add CPU and memory polling for AXIS OS 12.10+ (#19639) - redundantredundancy
- Add minimal support/detection for tbs-kylone (#19634) - Npeca75
- Added detection for Digital Logger devices (#19631) - laf
- Updated Huber+Suhner OS Data (#19630) - kivu8
- Adva FSP150cc XG210 PSU and Fan Support (#19625) - opalivan
- Fix to add TiMOS BGP peer description (#19614) - matheorism
- Refactor & add support for sti440 terra receivers (#19600) - Npeca75
- Add health sensors for NetAgent2 UPS devices (#19521) - laf
- Metaview support (#19492) - laf
- Siklu MultiHaul Terragraph sensor support (#19487) - bdg-robert
- EnGenius Switch OS detection for ECS and EWS line of switches (#19471) - bdg-robert
- Improve AP radio polling and add per-subscriber sensors (#19462) - isolson
- Add support for Teltonika OTD Series (OTD500) (#19113) - glennmatth
Webui
- Filter widget ?filter= avoids saved (#19687) - murrant
- Ports filter by device hostname (#19682) - murrant
- Fix device overview port links (#19676) - murrant
- Make port has errors a standard filter (#19675) - murrant
- Migrate user permissions page to Laravel (#19627) - murrant
- Cache display name (#19618) - murrant
- Dashboard (Gridstack) fixes (#19610) - murrant
- Panel "table" slot quick fix (#19602) - murrant
- Panel component glow up (#19595) - murrant
- Device delete pages to Laravel (#19594) - murrant
- Convert iftype page to Laravel (#19590) - eskyuu
- SNMP Settings: mask credentials with visibility toggle (#19542) - Palerm0
- Alert operations mute (#19535) - laf
- Fix for device dependency host to respect global display name template (#19534) - bdg-robert
- Prevent blank windows or tabs when opening SSH/Telnet (#19532) - bdg-robert
- Fixes to availability device widget (#19524) - murrant
- Add ability to show single graph for Port Group (#19518) - laf
- Replace Gridster with Gridstack for dashboard widgets (#19517) - laf
- Fix Device Availability Widget when no inserted exists (#19515) - murrant
- Improve visibility of and/or selector in alert rule builder (#19499) - laf
- Health sensors widget (#19497) - laf
- Added QoS data associated with ports (#19491) - laf
Graphs
Snmp Traps
- Add EES power alarm SNMP trap handler (#19670) - craig-nokia
Api
Settings
Discovery
- Updated tpdin sensors skipping 0 values (#19507) - laf
- Add FDB table support for Nokia TiMOS devices (#18713) - peelman
Bug
- Fixed MapQuest API url (#19671) - szastan
- Remove dead scopeLimit on Notification model (breaks daily.sh under Laravel 11) (#19669) - swaymel
- Fix double-encoded builder/extra in alert rule legacy API (#19666) - Starson323
- Fix graph time picker redirect 404 (#19648) - HaradaKumiko
- Fixes Xdsl.php when the SNMP response data in an unexpected format (#19641) - sherlvoodi-create
- Fix link to port on Inventory page (#19597) - laf
- Added more defaults to OSPFv3 area fields missing from Arista (#19588) - laf
- Fix logic for dev commands (#19586) - mpikzink
- Fix SSL Certificate menu hiding on lower sized screen res (#19571) - laf
- Mistyped variable name breaking custom OID (#19569) - JHarmonPMU
- Handle GBK-encoded interface names and descriptions in ports polling (#19528) - Yish1
- Zynos/Zyxel fix port ifName between 50 and 63 (#19341) - Yanonix
Refactor
Cleanup
- Add net-snmp version to about (#19612) - murrant
- Strong typing for table and select controllers (#19572) - murrant
- Cleanup generate_sensor_link (#19523) - mpikzink
- Cleanup get_port_by_id (#19480) - mpikzink
Translation
Misc
- Fix uninitialized variables in smokeping graph templates (#19599) - bdg-robert
- Add check_dnssec_delegation override (#19591) - 49phil
- Fall back to IEEE 802.3ad LAG-MIB when ifStackTable is missing (#19574) - shward
- Fix BGP peer device links incorrect with reused IP address space (#19394) - Starson323
Dependencies
- PHP Dependency updates: (#19644) - murrant
- Bump fast-uri from 3.1.0 to 3.1.2 (#19636) - dependabot
- Bump axios from 1.15.0 to 1.15.2 (#19619) - dependabot
- Bump phpseclib/phpseclib from 3.0.51 to 3.0.52 (#19617) - dependabot
- Bump postcss and vue-loader (#19570) - dependabot
Breaking Changes
- Removed default fortigate -> fortios match for Oxidized config
- Changed default APP_TRUSTED_PROXIES from unspecified to 127.0.0.1
Security Fixes
- Composer wrapper escape args — mitigates command injection
- Fix netmap XSS
- Various XSS fixes
- Fix legacy page title XSS
- Fix XSS in edituser
- Fix Device Type Widget access
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Beta — feedback welcome: [email protected]