lin-snow has 17 CVEs on record. Disclosures have slowed: 2 in the last 90 days after 15 in the 90 before. The busiest recent month was May 2026 with 8. The median CVSS is 6.5 (medium). None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.5
- Publish → KEV
- —
- Last 90 days
- 2 prev 15
Worst active — by depth score
CVE-2026-79662High· 8.0Ech0's OAuth redirect URI validation ignores path component, enables exchange-code theft44CVE-2026-79659High· 7.7Ech0 has Server-Side Request Forgery (SSRF) via Connect Handler fetchPeerConnectInfo42CVE-2026-79667High· 7.6Ech0: Scoped admin access tokens can bypass least-privilege controls on privileged endpoints, including backup export42GHSA-mqxv-9rm6-w8qcHighEch0: ParseAcceptLanguage `_` separator bypass enables ~70x CPU amplification via Accept-Language header in i18n.Middleware41GHSA-fpw6-hrg5-q5x5High· 7.4ech0's acess tokens with expiry=never cannot be revoked: logout panics, delete does not blacklist JTI41
lin-snow vulnerabilities
CVEs affecting lin-snow, newest first. Open any entry for full detail, references, and exploit status.
17 CVEsRSS
GO-2026-5981NoneEch0: ParseAcceptLanguage `_` separator bypass enables ~70x CPU amplification via Accept-Language header in i18n.Middleware in github.com…
Ech0: ParseAcceptLanguage `_` separator bypass enables ~70x CPU amplification via Accept-Language header in i18n.Middleware in github.com/lin-snow/ech0
GHSA-mqxv-9rm6-w8qcHighEch0: ParseAcceptLanguage `_` separator bypass enables ~70x CPU amplification via Accept-Language header in i18n.Middleware
Ech0: ParseAcceptLanguage `_` separator bypass enables ~70x CPU amplification via Accept-Language header in i18n.Middleware
CVE-2026-79660Medium· 5.3Ech0 comment model's Email field returned on public /api/comments endpoints
Ech0 comment model's Email field returned on public /api/comments endpoints
CVE-2026-79668Medium· 5.3Ech0's Unauthenticated Like Endpoint Enables Arbitrary Engagement Metric Inflation
Ech0's Unauthenticated Like Endpoint Enables Arbitrary Engagement Metric Inflation
CVE-2026-79661Medium· 6.5Ech0 allows PUT /api/echo/like/:id unauthenticated: anonymous callers to modify any echo's fav_count
Ech0 allows PUT /api/echo/like/:id unauthenticated: anonymous callers to modify any echo's fav_count
CVE-2026-79662High· 8.0Ech0's OAuth redirect URI validation ignores path component, enables exchange-code theft
Ech0's OAuth redirect URI validation ignores path component, enables exchange-code theft
CVE-2026-79664High· 7.4ech0's acess tokens with expiry=never cannot be revoked: logout panics, delete does not blacklist JTI
ech0's acess tokens with expiry=never cannot be revoked: logout panics, delete does not blacklist JTI
CVE-2026-79659High· 7.7Ech0 has Server-Side Request Forgery (SSRF) via Connect Handler fetchPeerConnectInfo
Ech0 has Server-Side Request Forgery (SSRF) via Connect Handler fetchPeerConnectInfo
CVE-2026-79663Medium· 4.8Ech0's RSS feed renders unescaped tag names and raw-HTML markdown, stored XSS against subscribers
Ech0's RSS feed renders unescaped tag names and raw-HTML markdown, stored XSS against subscribers
GHSA-fpw6-hrg5-q5x5High· 7.4ech0's acess tokens with expiry=never cannot be revoked: logout panics, delete does not blacklist JTI
ech0's acess tokens with expiry=never cannot be revoked: logout panics, delete does not blacklist JTI
CVE-2026-79669Medium· 4.3Ech0's Missing Authorization on System Logs Allows Non-Admin Information Disclosure
Ech0's Missing Authorization on System Logs Allows Non-Admin Information Disclosure
CVE-2026-79671Medium· 5.5Ech0 has SSRF via DNS Resolution Bypass in Webhook URL Validation
Ech0 has SSRF via DNS Resolution Bypass in Webhook URL Validation
CVE-2026-79673Medium· 6.5Ech0 Scope Bypass: profile:read Access Token Can Change Admin Password and Escalate to Unrestricted Session
Ech0 Scope Bypass: profile:read Access Token Can Change Admin Password and Escalate to Unrestricted Session
CVE-2026-79672Medium· 5.5Ech0 Comment Panel Endpoints Missing RequireScopes Middleware — Scoped Access Token Bypass
Ech0 Comment Panel Endpoints Missing RequireScopes Middleware — Scoped Access Token Bypass
CVE-2026-79666Medium· 6.5Ech0: Missing authorization on dashboard log endpoints allows low-privilege users to access sensitive system logs
Ech0: Missing authorization on dashboard log endpoints allows low-privilege users to access sensitive system logs
CVE-2026-79670Medium· 4.8Ech0 has Stored XSS via SVG Upload and Content-Type Validation Bypass in File Upload
Ech0 has Stored XSS via SVG Upload and Content-Type Validation Bypass in File Upload
CVE-2026-79667High· 7.6Ech0: Scoped admin access tokens can bypass least-privilege controls on privileged endpoints, including backup export
Ech0: Scoped admin access tokens can bypass least-privilege controls on privileged endpoints, including backup export