{"id":"GHSA-55wf-5m3q-6jjf","summary":"ipl/web is vulnerable to reflected XSS by malformed search requests","details":"### Impact\nThe vulnerability allows an attacker to inject malicious Javascript into a victim's browser to run it in the context of Icinga Web. The victim needs to visit a specifically prepared website and may have no immediate chance to notice any wrongdoing.\n\n### Patches\nVersion 0.13.1 includes a fix for this. It will be published as part of `icinga-php-library` version 0.19.2.\n\n### Workarounds\nEnable the Content-Security-Policy (CSP) in the general configuration of Icinga Web available since version 2.12.0.\n\n### References\nNone","aliases":["CVE-2026-42224"],"modified":"2026-09-10T03:50:42.911930506Z","published":"2026-04-29T21:01:55Z","database_specific":{"github_reviewed_at":"2026-04-29T21:01:55Z","nvd_published_at":"2026-05-08T23:16:35Z","cwe_ids":["CWE-79"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/Icinga/ipl-web/security/advisories/GHSA-55wf-5m3q-6jjf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42224"},{"type":"WEB","url":"https://github.com/Icinga/ipl-web/commit/f387e92504d7a03bb857d1aee9b7410e06dd065d"},{"type":"PACKAGE","url":"https://github.com/Icinga/ipl-web"},{"type":"WEB","url":"https://github.com/Icinga/ipl-web/releases/tag/v0.10.3"},{"type":"WEB","url":"https://github.com/Icinga/ipl-web/releases/tag/v0.13.1"}],"affected":[{"package":{"name":"ipl/web","ecosystem":"Packagist","purl":"pkg:composer/ipl/web"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0.11.0"},{"fixed":"0.13.1"}]}],"versions":["0.11.0","v0.11.1","v0.12.0","v0.13.0"],"database_specific":{"last_known_affected_version_range":"\u003c= 0.13.0","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-55wf-5m3q-6jjf/GHSA-55wf-5m3q-6jjf.json"}},{"package":{"name":"ipl/web","ecosystem":"Packagist","purl":"pkg:composer/ipl/web"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.10.3"}]}],"versions":["v0.1.0","v0.10.0","v0.10.1","v0.10.2","v0.2.0","v0.2.1","v0.3.0","v0.4.0","v0.5.0","v0.6.0","v0.7.0","v0.7.1","v0.8.0","v0.9.0","v0.9.1","v0.9.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-55wf-5m3q-6jjf/GHSA-55wf-5m3q-6jjf.json","last_known_affected_version_range":"\u003c= 0.10.2"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H"}]}