Executive brief
Ech0 is an open-source authentication and access control management service used to issue and revoke API tokens. A critical flaw prevents proper revocation of tokens configured to never expire, allowing attackers who steal such a token to maintain permanent authenticated access to APIs and services. The only way to invalidate a compromised token is to rotate the signing key globally, disrupting all users across the entire system.
Technical details
Ech0 before 4.7.3 fails to revoke access tokens created with expiry set to "never." The vulnerability stems from three independent failures in revocation logic: (1) the logout handler dereferences a nil ExpiresAt field when processing never-expire tokens, causing a panic and preventing the token from reaching the blacklist; (2) the RevokeToken function skips blacklist writes when remainTTL is zero; (3) the admin delete action removes the database record but does not call RevokeToken or write to the JTI blacklist. Once a never-expire token is stolen, it remains cryptographically valid indefinitely because JWT signature validation succeeds and the middleware does not consult a blacklist for such tokens. The only remediation is to rotate the JWT_SECRET, which invalidates all tokens for all users. This is a token authentication bypass with network-level attack surface.
Affected products
- lin-snow Ech0 < 4.7.3
Timeline
- 2026-05-03: disclosed: GitHub Security Advisory published
- 2026-04-01: patched: Version 4.7.3 released (estimated based on advisory date)
- 2026-08-25: advisory: CVE-2026-79664 published