Junglewise Threat Intelligence

CVE-2026-79658: Ech0 ReDoS in Accept-Language header processing via i18n middleware

CVE-2026-79658 · Severity: high · CVSS 7.5 · Published 2026-08-25

Technologies: Lin-Snow Ech0. Vendors: Lin-Snow.

Executive brief

Ech0 is a web application framework that processes HTTP headers to determine a user's language preference. The application fails to validate the Accept-Language header before processing it, allowing an attacker to craft specially-formatted headers that consume excessive CPU resources. An unauthenticated attacker can send a single malicious request to consume ~1.5 seconds of CPU; multiple concurrent requests can completely disable the server.

Technical details

This is a ReDoS (regular expression denial of service) vulnerability affecting Ech0's i18n middleware, which processes the Accept-Language HTTP header on every request without size or format restrictions. The header is passed unfiltered to go-i18n's NewLocalizer, which invokes golang.org/x/text/language.ParseAcceptLanguage. Although CVE-2022-32149 previously mitigated this parser by capping '-' characters at 1000, the parser internally aliases '_' characters to '-' before parsing, but the guard does not count '_' characters. An attacker can construct a 1 MiB header using '_' separators (e.g., repeated '_abcdefghi' tokens) that bypasses the guard and triggers quadratic-time parsing behavior. The attack requires no authentication and can be triggered by sending an HTTP GET request to any endpoint. Patched in Ech0 5.0.1 and later.

Affected products

  • lin-snow Ech0 before 5.0.1

Timeline

  • 2026-06-04: disclosed: GitHub Security Advisory GHSA-mqxv-9rm6-w8qc published
  • 2026-08-25: advisory: CVE-2026-79658 published in NVD

References

Related threats