VulnSea

github.com/lin-snow/ech0 vulnerabilities

CVEs whose affected-version data names the github.com/lin-snow/ech0 package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

17 CVEsRSS

GO-2026-5981None
2mo ago

Ech0: ParseAcceptLanguage `_` separator bypass enables ~70x CPU amplification via Accept-Language header in i18n.Middleware in github.com…

Ech0: ParseAcceptLanguage `_` separator bypass enables ~70x CPU amplification via Accept-Language header in i18n.Middleware in github.com/lin-snow/ech0

Sunlitlin-snow · github.com/lin-snow/ech0via OSV
GHSA-mqxv-9rm6-w8qcHigh
2mo ago

Ech0: ParseAcceptLanguage `_` separator bypass enables ~70x CPU amplification via Accept-Language header in i18n.Middleware

Ech0: ParseAcceptLanguage `_` separator bypass enables ~70x CPU amplification via Accept-Language header in i18n.Middleware

Twilightlin-snow · github.com/lin-snow/ech0via GHSA
CVE-2026-79660Medium· 5.3
4mo ago

Ech0 comment model's Email field returned on public /api/comments endpoints

Ech0 comment model's Email field returned on public /api/comments endpoints

Sunlitlin-snow · github.com/lin-snow/Ech0EPSS 0.24%via OSV
CVE-2026-79668Medium· 5.3
4mo ago

Ech0's Unauthenticated Like Endpoint Enables Arbitrary Engagement Metric Inflation

Ech0's Unauthenticated Like Endpoint Enables Arbitrary Engagement Metric Inflation

Sunlitlin-snow · github.com/lin-snow/ech0EPSS 0.26%via OSV
CVE-2026-79661Medium· 6.5
4mo ago

Ech0 allows PUT /api/echo/like/:id unauthenticated: anonymous callers to modify any echo's fav_count

Ech0 allows PUT /api/echo/like/:id unauthenticated: anonymous callers to modify any echo's fav_count

Sunlitlin-snow · github.com/lin-snow/Ech0EPSS 0.25%via OSV
CVE-2026-79662High· 8.0
4mo ago

Ech0's OAuth redirect URI validation ignores path component, enables exchange-code theft

Ech0's OAuth redirect URI validation ignores path component, enables exchange-code theft

Twilightlin-snow · github.com/lin-snow/Ech0EPSS 0.19%via OSV
CVE-2026-79664High· 7.4
4mo ago

ech0's acess tokens with expiry=never cannot be revoked: logout panics, delete does not blacklist JTI

ech0's acess tokens with expiry=never cannot be revoked: logout panics, delete does not blacklist JTI

Twilightlin-snow · github.com/lin-snow/ech0EPSS 0.22%via OSV
CVE-2026-79659High· 7.7
4mo ago

Ech0 has Server-Side Request Forgery (SSRF) via Connect Handler fetchPeerConnectInfo

Ech0 has Server-Side Request Forgery (SSRF) via Connect Handler fetchPeerConnectInfo

Twilightlin-snow · github.com/lin-snow/ech0EPSS 0.21%via OSV
CVE-2026-79663Medium· 4.8
4mo ago

Ech0's RSS feed renders unescaped tag names and raw-HTML markdown, stored XSS against subscribers

Ech0's RSS feed renders unescaped tag names and raw-HTML markdown, stored XSS against subscribers

Sunlitlin-snow · github.com/lin-snow/Ech0EPSS 0.15%via OSV
GHSA-fpw6-hrg5-q5x5High· 7.4
4mo ago

ech0's acess tokens with expiry=never cannot be revoked: logout panics, delete does not blacklist JTI

ech0's acess tokens with expiry=never cannot be revoked: logout panics, delete does not blacklist JTI

Twilightlin-snow · github.com/lin-snow/ech0via OSV
CVE-2026-79669Medium· 4.3
5mo ago

Ech0's Missing Authorization on System Logs Allows Non-Admin Information Disclosure

Ech0's Missing Authorization on System Logs Allows Non-Admin Information Disclosure

Sunlitlin-snow · github.com/lin-snow/ech0EPSS 0.17%via OSV
CVE-2026-79671Medium· 5.5
5mo ago

Ech0 has SSRF via DNS Resolution Bypass in Webhook URL Validation

Ech0 has SSRF via DNS Resolution Bypass in Webhook URL Validation

Sunlitlin-snow · github.com/lin-snow/ech0EPSS 0.24%via OSV
CVE-2026-79673Medium· 6.5
5mo ago

Ech0 Scope Bypass: profile:read Access Token Can Change Admin Password and Escalate to Unrestricted Session

Ech0 Scope Bypass: profile:read Access Token Can Change Admin Password and Escalate to Unrestricted Session

Sunlitlin-snow · github.com/lin-snow/ech0EPSS 0.24%via OSV
CVE-2026-79672Medium· 5.5
5mo ago

Ech0 Comment Panel Endpoints Missing RequireScopes Middleware — Scoped Access Token Bypass

Ech0 Comment Panel Endpoints Missing RequireScopes Middleware — Scoped Access Token Bypass

Sunlitlin-snow · github.com/lin-snow/ech0EPSS 0.19%via OSV
CVE-2026-79666Medium· 6.5
5mo ago

Ech0: Missing authorization on dashboard log endpoints allows low-privilege users to access sensitive system logs

Ech0: Missing authorization on dashboard log endpoints allows low-privilege users to access sensitive system logs

Sunlitlin-snow · github.com/lin-snow/ech0EPSS 0.28%via OSV
CVE-2026-79670Medium· 4.8
5mo ago

Ech0 has Stored XSS via SVG Upload and Content-Type Validation Bypass in File Upload

Ech0 has Stored XSS via SVG Upload and Content-Type Validation Bypass in File Upload

Sunlitlin-snow · github.com/lin-snow/ech0EPSS 0.15%via OSV
CVE-2026-79667High· 7.6
5mo ago

Ech0: Scoped admin access tokens can bypass least-privilege controls on privileged endpoints, including backup export

Ech0: Scoped admin access tokens can bypass least-privilege controls on privileged endpoints, including backup export

Twilightlin-snow · github.com/lin-snow/ech0EPSS 0.19%via OSV
github.com/lin-snow/ech0 vulnerabilities (CVEs) · VulnSea