<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-09T14:03:39.704870+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-268918</id>
    <title>EUVD-2026-268918</title>
    <updated>2026-10-09T14:03:39.759065+00:00</updated>
    <content>EUVD-2026-268918</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-268918"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-27016</id>
    <title>fkie_cve-2026-27016</title>
    <updated>2026-10-09T14:03:39.759113+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 24.10.0 through 26.1.1 are vulnerable to Stored XSS via the unit parameter in Custom OID. The Custom OID functionality lacks strip_tags() sanitization while other fields (name, oid, datatype) are sanitized. The unsanitized value is stored in the database and rendered without HTML escaping. This issue is fixed in version 26.2.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-27016"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-fqx6-693c-f55g</id>
    <title>GHSA-fqx6-693c-f55g — LibreNMS has a Stored XSS in Custom OID - unit parameter missing strip_tags()</title>
    <updated>2026-10-09T14:03:39.759161+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: librenms/librenms</p>
<p>### Summary
The `unit` parameter in Custom OID functionality lacks `strip_tags()` sanitization while other fields (`name`, `oid`, `datatype`) are sanitized. The unsanitized value is stored in the database and rendered without HTML escaping, allowing Stored XSS.</p>
<p>### Details
**Vulnerable Input Processing (`includes/html/forms/customoid.inc.php` lines 18-21):**
```php
$name = strip_tags((string) $_POST['name']);       // line 18 - SANITIZED
$oid = strip_tags((string) $_POST['oid']);         // line 19 - SANITIZED
$datatype = strip_tags((string) $_POST['datatype']);  // line 20 - SANITIZED
$unit = $_POST['unit'];                            // line 21 - NOT SANITIZED!
```</p>
<p>**Vulnerable Output (`graphs/customoid.inc.php` lines 13-20):**
```php
$customoid_unit = $customoid['customoid_unit'];  // Retrieved from DB
$customoid_current = \LibreNMS\Util\Number::formatSi(...) . $customoid_unit;
echo "...$customoid_current...";  // ECHOED WITHOUT ESCAPING!
```</p>
<p>### PoC</p>
<p>```python
#!/usr/bin/env python3
"""
XSS test for LibreNMS Custom OID - unit parameter
"""</p>
<p>import html as html_module
import re</p>
<p>def strip_tags(value):
    return re.sub(r'&lt;[^&gt;]*?&gt;', '', str(value))</p>
<p># Simulate form processing (customoid.inc.php lines 18-21)
test_inputs = {
    'name': '&lt;script&gt;alert(1)&lt;/script&gt;Test OID',
    'oid': '1.3.6.1.4.1.2021.10.1.3.1',
    'datatype': 'GAUGE',
    'unit': '&lt;script&gt;alert("XSS")&lt;/script&gt;',
}</p>
<p>name = strip_tags(test_inputs['name'])      # Sanitized
oid = strip_tags(test_inputs['oid…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-fqx6-693c-f55g"/>
  </entry>
</feed>
