{"id":"CVE-2026-55677","title":"github.com/labstack/echo: Echo: Unauthorized Information Disclosure via URL Path Decoding Discrepancy (CVE-2026-55677)","summary":"A flaw was found in Echo, a Go web framework. An attacker can exploit a disagreement in URL path decoding between the router and the static file handler. The router processes raw encoded paths, while the static file handler unescapes encod…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","cvssSource":"vendor","cwe":"CWE-22","vendor":"Red Hat","product":"Red Hat Enterprise Linux AppStream E4S (v.9.2)","affected":["ceph_storage 5","enterprise_linux 9","enterprise_linux_appstream_eus_v_10_0","enterprise_linux_appstream_v_10","enterprise_linux_appstream_v_8","enterprise_linux_appstream_e4s_v_9_2","enterprise_linux_appstream_eus_v_9_6","cluster_observability_operator 1.5.0","multicluster_global_hub 1.6.5","multicluster_global_hub 1.7.3","multicluster_global_hub 1.8.2","advanced_cluster_management_for_kubernetes 2.15","advanced_cluster_management_for_kubernetes 2.16","advanced_cluster_management_for_kubernetes 2.17"],"patched":["enterprise_linux_appstream_eus_v_10_0","enterprise_linux_appstream_v_10","enterprise_linux_appstream_v_8","enterprise_linux_appstream_e4s_v_9_2","enterprise_linux_appstream_eus_v_9_6","cluster_observability_operator 1.5.0","multicluster_global_hub 1.6.5","multicluster_global_hub 1.7.3","multicluster_global_hub 1.8.2","advanced_cluster_management_for_kubernetes 2.15","advanced_cluster_management_for_kubernetes 2.16","advanced_cluster_management_for_kubernetes 2.17"],"published":"2026-06-26","updated":"2026-09-21","sourceUpdated":"2026-09-21T11:40:59+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-55677.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-55677.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-55677"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2493622"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-55677"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55677"},{"url":"https://github.com/labstack/echo/security/advisories/GHSA-vfp3-v2gw-7wfq"},{"url":"https://access.redhat.com/errata/RHSA-2026:63134"},{"url":"https://access.redhat.com/errata/RHSA-2026:66432"},{"url":"https://access.redhat.com/errata/RHSA-2026:67148"},{"url":"https://access.redhat.com/errata/RHSA-2026:61585"},{"url":"https://access.redhat.com/errata/RHSA-2026:57541"},{"url":"https://access.redhat.com/errata/RHSA-2026:61314"},{"url":"https://access.redhat.com/errata/RHSA-2026:44622"},{"url":"https://access.redhat.com/errata/RHSA-2026:47149"},{"url":"https://access.redhat.com/errata/RHSA-2026:53530"},{"url":"https://access.redhat.com/errata/RHSA-2026:52946"},{"url":"https://access.redhat.com/errata/RHSA-2026:60389"},{"url":"https://access.redhat.com/errata/RHSA-2026:60391"},{"url":"https://access.redhat.com/errata/RHSA-2026:60386"},{"url":"https://github.com/labstack/echo/pull/3009"},{"url":"https://github.com/labstack/echo/pull/3011"},{"url":"https://github.com/labstack/echo/commit/8d1ae9d3360a71672418856d58753af25f2c3986"},{"url":"https://github.com/labstack/echo/commit/c3fa2a27ff92b2b8db360de614f999ef1da24725"},{"url":"https://github.com/labstack/echo/releases/tag/v4.15.3"},{"url":"https://github.com/labstack/echo/releases/tag/v5.2.0"},{"url":"https://github.com/advisories/GHSA-vfp3-v2gw-7wfq"}],"tags":["csaf","vex","red-hat","ghsa","go"],"epss":0.00431,"epssPercentile":0.36781,"aliases":["GHSA-vfp3-v2gw-7wfq"],"ecosystem":"go","ingestedAt":"2026-08-25T16:28:50.900Z","slug":"CVE-2026-55677","body":"## Overview\n\nA flaw was found in Echo, a Go web framework. An attacker can exploit a disagreement in URL path decoding between the router and the static file handler. The router processes raw encoded paths, while the static file handler unescapes encoded forward slashes. This allows an attacker to bypass route-level access controls, leading to unauthorized information disclosure by reading static files.\n\n## Vendor advisories\n\n- **RHSA-2026:63134** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v. 10.0) · released 2026-09-03 · [advisory](https://access.redhat.com/errata/RHSA-2026:63134)\n- **RHSA-2026:66432** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10) · released 2026-09-11 · [advisory](https://access.redhat.com/errata/RHSA-2026:66432)\n- **RHSA-2026:67148** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 8) · released 2026-09-14 · [advisory](https://access.redhat.com/errata/RHSA-2026:67148)\n- **RHSA-2026:61585** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.9.2) · released 2026-08-31 · [advisory](https://access.redhat.com/errata/RHSA-2026:61585)\n- **RHSA-2026:57541** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v.9.6) · released 2026-08-20 · [advisory](https://access.redhat.com/errata/RHSA-2026:57541)\n- **RHSA-2026:61314** · Red Hat · fixed in: Cluster Observability Operator 1.5.0 · released 2026-08-31 · [advisory](https://access.redhat.com/errata/RHSA-2026:61314)\n- **RHSA-2026:44622** · Red Hat · fixed in: Multicluster Global Hub 1.6.5 · released 2026-07-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:44622)\n- **RHSA-2026:47149** · Red Hat · fixed in: Multicluster Global Hub 1.7.3 · released 2026-07-28 · [advisory](https://access.redhat.com/errata/RHSA-2026:47149)\n- **RHSA-2026:53530** · Red Hat · fixed in: Multicluster Global Hub 1.7.3 · released 2026-08-11 · [advisory](https://access.redhat.com/errata/RHSA-2026:53530)\n- **RHSA-2026:52946** · Red Hat · fixed in: Multicluster Global Hub 1.8.2 · released 2026-08-10 · [advisory](https://access.redhat.com/errata/RHSA-2026:52946)\n- **RHSA-2026:60389** · Red Hat · fixed in: Red Hat Advanced Cluster Management for Kubernetes 2.15 · released 2026-08-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:60389)\n- **Red Hat VEX** · Important · affected: Red Hat Ceph Storage 5, Red Hat Enterprise Linux 9 · no fix planned: Red Hat Ceph Storage 5, Red Hat Enterprise Linux 9 · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-55677.json)\n\n**github.com/labstack/echo: Echo: Unauthorized Information Disclosure via URL Path Decoding Discrepancy** — rated Important by Red Hat. Released 2026-06-26, updated 2026-09-21.\n\nAffected:\n\n- Red Hat Ceph Storage 5\n- Red Hat Enterprise Linux 9\n\nFixed:\n\n- Red Hat Enterprise Linux AppStream EUS (v. 10.0)\n- Red Hat Enterprise Linux AppStream (v. 10)\n- Red Hat Enterprise Linux AppStream (v. 8)\n- Red Hat Enterprise Linux AppStream E4S (v.9.2)\n- Red Hat Enterprise Linux AppStream EUS (v.9.6)\n- Cluster Observability Operator 1.5.0\n- Multicluster Global Hub 1.6.5\n- Multicluster Global Hub 1.7.3\n- Multicluster Global Hub 1.8.2\n- Red Hat Advanced Cluster Management for Kubernetes 2.15\n- Red Hat Advanced Cluster Management for Kubernetes 2.16\n- Red Hat Advanced Cluster Management for Kubernetes 2.17\n\nNo fix planned:\n\n- Red Hat Ceph Storage 5\n- Red Hat Enterprise Linux 9\n\nNot affected:\n\n- Cluster Observability Operator 1.5.0\n- Multicluster Global Hub 1.6.5\n- Multicluster Global Hub 1.7.3\n- Multicluster Global Hub 1.8.2\n- Red Hat Advanced Cluster Management for Kubernetes 2.15\n- Red Hat Advanced Cluster Management for Kubernetes 2.16\n- Red Hat Advanced Cluster Management for Kubernetes 2.17\n- Red Hat Advanced Cluster Management for Kubernetes 2\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 8\n\n## Remediation\n\nFor details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:63134\nFor details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:66432\nFor details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:67148\n\nWorkarounds / mitigations:\n\n- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.\n\n## Package advisory (CVE-2026-55677)\n\nAffected packages:\n\n- `github.com/labstack/echo/v5 < 5.2.0`\n- `github.com/labstack/echo/v4 < 4.15.3`\n- `github.com/labstack/echo <= 3.3.10`\n\nPatched in:\n\n- `github.com/labstack/echo/v5 5.2.0`\n- `github.com/labstack/echo/v4 4.15.3`\n\nSource: https://github.com/advisories/GHSA-vfp3-v2gw-7wfq","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}