Executive brief
Ech0 is a web application framework that processes HTTP headers to determine a user's language preference. The application fails to validate the Accept-Language header before processing it, allowing an attacker to craft specially-formatted headers that consume excessive CPU resources. An unauthenticated attacker can send a single malicious request to consume ~1.5 seconds of CPU; multiple concurrent requests can completely disable the server.
Technical details
This is a ReDoS (regular expression denial of service) vulnerability affecting Ech0's i18n middleware, which processes the Accept-Language HTTP header on every request without size or format restrictions. The header is passed unfiltered to go-i18n's NewLocalizer, which invokes golang.org/x/text/language.ParseAcceptLanguage. Although CVE-2022-32149 previously mitigated this parser by capping '-' characters at 1000, the parser internally aliases '_' characters to '-' before parsing, but the guard does not count '_' characters. An attacker can construct a 1 MiB header using '_' separators (e.g., repeated '_abcdefghi' tokens) that bypasses the guard and triggers quadratic-time parsing behavior. The attack requires no authentication and can be triggered by sending an HTTP GET request to any endpoint. Patched in Ech0 5.0.1 and later.
Affected products
- lin-snow Ech0 before 5.0.1
Timeline
- 2026-06-04: disclosed: GitHub Security Advisory GHSA-mqxv-9rm6-w8qc published
- 2026-08-25: advisory: CVE-2026-79658 published in NVD