{"schema_version":1,"title":"Lin-Snow Ech0 vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 25 vulnerabilities in Lin-Snow Ech0: 0 in the last 7 days and 18 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-79673, was published on 25 August 2026.","url":"https://junglewise.ai/threats/technologies/ech0","json_url":"https://junglewise.ai/threats/technologies/ech0.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/ech0","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":9,"all_time":25,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":18,"last_365_days":25},"latest":[{"cve":"CVE-2026-79673","cvss":6.5,"epss":0.0043,"slug":"cve-2026-79673-ech0-scope-bypass-in-put-user-endpoint-via-profile-read-token","title":"Ech0 scope bypass in PUT /user endpoint via profile:read token","severity":"medium","exploited":false,"published_at":"2026-08-25T12:16:35.68+00:00","url":"https://junglewise.ai/threats/cve-2026-79673-ech0-scope-bypass-in-put-user-endpoint-via-profile-read-token"},{"cve":"CVE-2026-79672","cvss":5.5,"epss":0.0032,"slug":"cve-2026-79672-ech0-authorization-bypass-in-comment-panel-endpoints","title":"Ech0 authorization bypass in comment panel endpoints","severity":"medium","exploited":false,"published_at":"2026-08-25T12:16:35.537+00:00","url":"https://junglewise.ai/threats/cve-2026-79672-ech0-authorization-bypass-in-comment-panel-endpoints"},{"cve":"CVE-2026-79671","cvss":5.5,"epss":0.0031,"slug":"cve-2026-79671-ech0-server-side-request-forgery-in-webhook-url-validation","title":"Ech0 server-side request forgery in webhook URL validation","severity":"medium","exploited":false,"published_at":"2026-08-25T12:16:35.39+00:00","url":"https://junglewise.ai/threats/cve-2026-79671-ech0-server-side-request-forgery-in-webhook-url-validation"},{"cve":"CVE-2026-79670","cvss":4.8,"epss":0.0025,"slug":"cve-2026-79670-ech0-stored-cross-site-scripting-in-file-upload","title":"Ech0 stored cross-site scripting in file upload","severity":"medium","exploited":false,"published_at":"2026-08-25T12:16:35.247+00:00","url":"https://junglewise.ai/threats/cve-2026-79670-ech0-stored-cross-site-scripting-in-file-upload"},{"cve":"CVE-2026-79669","cvss":4.3,"epss":0.0021,"slug":"cve-2026-79669-ech0-missing-authorization-on-system-log-endpoints","title":"Ech0 missing authorization on system log endpoints","severity":"medium","exploited":false,"published_at":"2026-08-25T12:16:35.107+00:00","url":"https://junglewise.ai/threats/cve-2026-79669-ech0-missing-authorization-on-system-log-endpoints"},{"cve":"CVE-2026-79668","cvss":5.3,"epss":0.0043,"slug":"cve-2026-79668-ech0-authentication-bypass-in-like-endpoint","title":"Ech0 authentication bypass in like endpoint","severity":"medium","exploited":false,"published_at":"2026-08-25T12:16:34.967+00:00","url":"https://junglewise.ai/threats/cve-2026-79668-ech0-authentication-bypass-in-like-endpoint"},{"cve":"CVE-2026-79667","cvss":7.6,"epss":0.0032,"slug":"cve-2026-79667-ech0-scoped-access-token-bypass-in-admin-routes","title":"Ech0 scoped access token bypass in admin routes","severity":"high","exploited":false,"published_at":"2026-08-25T12:16:34.813+00:00","url":"https://junglewise.ai/threats/cve-2026-79667-ech0-scoped-access-token-bypass-in-admin-routes"},{"cve":"CVE-2026-79666","cvss":6.5,"epss":0.0039,"slug":"cve-2026-79666-ech0-missing-authorization-on-dashboard-log-endpoints","title":"Ech0 missing authorization on dashboard log endpoints","severity":"medium","exploited":false,"published_at":"2026-08-25T12:16:34.67+00:00","url":"https://junglewise.ai/threats/cve-2026-79666-ech0-missing-authorization-on-dashboard-log-endpoints"},{"cve":"CVE-2026-79665","cvss":8.8,"epss":0.0051,"slug":"cve-2026-79665-ech0-authorization-bypass-in-requirescopes-middleware","title":"Ech0 authorization bypass in RequireScopes middleware","severity":"high","exploited":false,"published_at":"2026-08-25T12:16:34.523+00:00","url":"https://junglewise.ai/threats/cve-2026-79665-ech0-authorization-bypass-in-requirescopes-middleware"},{"cve":"CVE-2026-79664","cvss":7.4,"epss":0.0027,"slug":"cve-2026-79664-ech0-access-token-revocation-bypass-with-never-expire-tokens","title":"Ech0 access token revocation bypass with never-expire tokens","severity":"high","exploited":false,"published_at":"2026-08-25T12:16:34.37+00:00","url":"https://junglewise.ai/threats/cve-2026-79664-ech0-access-token-revocation-bypass-with-never-expire-tokens"},{"cve":"CVE-2026-79663","cvss":4.8,"epss":0.0025,"slug":"cve-2026-79663-ech0-stored-cross-site-scripting-in-rss-feed","title":"Ech0 stored cross-site scripting in RSS feed","severity":"medium","exploited":false,"published_at":"2026-08-25T12:16:33.627+00:00","url":"https://junglewise.ai/threats/cve-2026-79663-ech0-stored-cross-site-scripting-in-rss-feed"},{"cve":"CVE-2026-79662","cvss":8,"epss":0.0032,"slug":"cve-2026-79662-ech0-oauth-redirect-uri-validation-bypass","title":"Ech0 OAuth redirect URI validation bypass","severity":"high","exploited":false,"published_at":"2026-08-25T12:16:31.47+00:00","url":"https://junglewise.ai/threats/cve-2026-79662-ech0-oauth-redirect-uri-validation-bypass"},{"cve":"CVE-2026-79661","cvss":6.5,"epss":0.0043,"slug":"cve-2026-79661-ech0-unauthenticated-fav-count-modification","title":"Ech0 unauthenticated fav_count modification","severity":"medium","exploited":false,"published_at":"2026-08-25T12:16:29.87+00:00","url":"https://junglewise.ai/threats/cve-2026-79661-ech0-unauthenticated-fav-count-modification"},{"cve":"CVE-2026-79660","cvss":5.3,"epss":0.0041,"slug":"cve-2026-79660-ech0-email-disclosure-via-public-api-endpoints","title":"Ech0 email disclosure via public API endpoints","severity":"medium","exploited":false,"published_at":"2026-08-25T12:16:29.617+00:00","url":"https://junglewise.ai/threats/cve-2026-79660-ech0-email-disclosure-via-public-api-endpoints"},{"cve":"CVE-2026-79659","cvss":7.7,"epss":0.0026,"slug":"cve-2026-79659-ech0-server-side-request-forgery-in-fetchpeerconnectinfo","title":"Ech0 server-side request forgery in fetchPeerConnectInfo","severity":"high","exploited":false,"published_at":"2026-08-25T12:16:29.38+00:00","url":"https://junglewise.ai/threats/cve-2026-79659-ech0-server-side-request-forgery-in-fetchpeerconnectinfo"},{"cve":"CVE-2026-79658","cvss":7.5,"epss":0.0051,"slug":"cve-2026-79658-ech0-redos-in-accept-language-header-processing-via-i18n","title":"Ech0 ReDoS in Accept-Language header processing via i18n middleware","severity":"high","exploited":false,"published_at":"2026-08-25T12:16:29.123+00:00","url":"https://junglewise.ai/threats/cve-2026-79658-ech0-redos-in-accept-language-header-processing-via-i18n"},{"cve":"CVE-2026-77151","cvss":3.7,"epss":0.0037,"slug":"cve-2026-77151-lin-snow-ech0-weak-cryptographic-algorithm-in-md5encrypt","title":"lin-snow Ech0 weak cryptographic algorithm in MD5Encrypt","severity":"low","exploited":false,"published_at":"2026-08-20T20:17:47.253+00:00","url":"https://junglewise.ai/threats/cve-2026-77151-lin-snow-ech0-weak-cryptographic-algorithm-in-md5encrypt"},{"cvss":7.5,"slug":"lin-snow-ech0-cpu-amplification-in-i18n-middleware-fefbca41","title":"lin-snow Ech0 CPU amplification in i18n Middleware","severity":"high","exploited":false,"published_at":"2026-07-14T19:58:54+00:00","url":"https://junglewise.ai/threats/lin-snow-ech0-cpu-amplification-in-i18n-middleware-fefbca41"},{"cve":"CVE-2026-55677","cvss":7.5,"epss":0.0043,"slug":"cve-2026-55677-labstack-echo-authorization-bypass-in-static-file-handler","title":"Labstack Echo authorization bypass in static file handler","severity":"high","exploited":false,"published_at":"2026-06-26T17:16:34.203+00:00","url":"https://junglewise.ai/threats/cve-2026-55677-labstack-echo-authorization-bypass-in-static-file-handler"},{"cvss":4.8,"slug":"lin-snow-ech0-stored-xss-via-svg-upload-and-content-type-bypass-70c0cc9e","title":"lin-snow Ech0 stored XSS via SVG upload and Content-Type bypass","severity":"medium","exploited":false,"published_at":"2026-04-10T19:50:01+00:00","url":"https://junglewise.ai/threats/lin-snow-ech0-stored-xss-via-svg-upload-and-content-type-bypass-70c0cc9e"},{"cvss":5.5,"slug":"lin-snow-ech0-ssrf-via-dns-resolution-bypass-in-webhooks-5b02482e","title":"lin-snow Ech0 SSRF via DNS resolution bypass in webhooks","severity":"medium","exploited":false,"published_at":"2026-04-10T19:49:48+00:00","url":"https://junglewise.ai/threats/lin-snow-ech0-ssrf-via-dns-resolution-bypass-in-webhooks-5b02482e"},{"cvss":4.3,"slug":"lin-snow-ech0-missing-authorization-in-system-log-endpoints-77516f8c","title":"lin-snow Ech0 missing authorization in system log endpoints","severity":"medium","exploited":false,"published_at":"2026-04-10T19:49:33+00:00","url":"https://junglewise.ai/threats/lin-snow-ech0-missing-authorization-in-system-log-endpoints-77516f8c"},{"cvss":6.5,"slug":"lin-snow-ech0-scope-bypass-in-put-user-endpoint-64820ae3","title":"lin-snow Ech0 scope bypass in PUT /user endpoint","severity":"medium","exploited":false,"published_at":"2026-04-10T19:49:13+00:00","url":"https://junglewise.ai/threats/lin-snow-ech0-scope-bypass-in-put-user-endpoint-64820ae3"},{"cvss":6.5,"slug":"lin-snow-ech0-missing-authorization-in-dashboard-log-endpoints-46070e38","title":"lin-snow Ech0 missing authorization in dashboard log endpoints","severity":"medium","exploited":false,"published_at":"2026-04-10T19:40:02+00:00","url":"https://junglewise.ai/threats/lin-snow-ech0-missing-authorization-in-dashboard-log-endpoints-46070e38"},{"cvss":7.6,"slug":"lin-snow-ech0-authorization-bypass-in-privileged-endpoints-56fe438e","title":"lin-snow Ech0 authorization bypass in privileged endpoints","severity":"high","exploited":false,"published_at":"2026-04-10T19:39:46+00:00","url":"https://junglewise.ai/threats/lin-snow-ech0-authorization-bypass-in-privileged-endpoints-56fe438e"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":16},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[],"technology":{"hub":true,"name":"Lin-Snow Ech0","slug":"ech0","vendor":{"name":"Lin-Snow","slug":"lin-snow","url":"https://junglewise.ai/threats/vendors/lin-snow"},"aliases":["echo"],"category":"library","homepage":"https://github.com/lin-snow/ech0","repo_url":"https://github.com/lin-snow/ech0","description":"Ech0 is a high-performance, lightweight, and easy-to-use web framework for the Go programming language.","url":"https://junglewise.ai/threats/technologies/ech0"},"most_severe":[{"cve":"CVE-2026-79665","cvss":8.8,"epss":0.0051,"slug":"cve-2026-79665-ech0-authorization-bypass-in-requirescopes-middleware","title":"Ech0 authorization bypass in RequireScopes middleware","severity":"high","exploited":false,"published_at":"2026-08-25T12:16:34.523+00:00","url":"https://junglewise.ai/threats/cve-2026-79665-ech0-authorization-bypass-in-requirescopes-middleware"},{"cve":"CVE-2026-79662","cvss":8,"epss":0.0032,"slug":"cve-2026-79662-ech0-oauth-redirect-uri-validation-bypass","title":"Ech0 OAuth redirect URI validation bypass","severity":"high","exploited":false,"published_at":"2026-08-25T12:16:31.47+00:00","url":"https://junglewise.ai/threats/cve-2026-79662-ech0-oauth-redirect-uri-validation-bypass"},{"cve":"CVE-2026-79659","cvss":7.7,"epss":0.0026,"slug":"cve-2026-79659-ech0-server-side-request-forgery-in-fetchpeerconnectinfo","title":"Ech0 server-side request forgery in fetchPeerConnectInfo","severity":"high","exploited":false,"published_at":"2026-08-25T12:16:29.38+00:00","url":"https://junglewise.ai/threats/cve-2026-79659-ech0-server-side-request-forgery-in-fetchpeerconnectinfo"},{"cve":"CVE-2026-79667","cvss":7.6,"epss":0.0032,"slug":"cve-2026-79667-ech0-scoped-access-token-bypass-in-admin-routes","title":"Ech0 scoped access token bypass in admin routes","severity":"high","exploited":false,"published_at":"2026-08-25T12:16:34.813+00:00","url":"https://junglewise.ai/threats/cve-2026-79667-ech0-scoped-access-token-bypass-in-admin-routes"},{"cvss":7.6,"slug":"lin-snow-ech0-authorization-bypass-in-privileged-endpoints-56fe438e","title":"lin-snow Ech0 authorization bypass in privileged endpoints","severity":"high","exploited":false,"published_at":"2026-04-10T19:39:46+00:00","url":"https://junglewise.ai/threats/lin-snow-ech0-authorization-bypass-in-privileged-endpoints-56fe438e"},{"cve":"CVE-2026-79658","cvss":7.5,"epss":0.0051,"slug":"cve-2026-79658-ech0-redos-in-accept-language-header-processing-via-i18n","title":"Ech0 ReDoS in Accept-Language header processing via i18n middleware","severity":"high","exploited":false,"published_at":"2026-08-25T12:16:29.123+00:00","url":"https://junglewise.ai/threats/cve-2026-79658-ech0-redos-in-accept-language-header-processing-via-i18n"},{"cve":"CVE-2026-55677","cvss":7.5,"epss":0.0043,"slug":"cve-2026-55677-labstack-echo-authorization-bypass-in-static-file-handler","title":"Labstack Echo authorization bypass in static file handler","severity":"high","exploited":false,"published_at":"2026-06-26T17:16:34.203+00:00","url":"https://junglewise.ai/threats/cve-2026-55677-labstack-echo-authorization-bypass-in-static-file-handler"},{"cvss":7.5,"slug":"lin-snow-ech0-cpu-amplification-in-i18n-middleware-fefbca41","title":"lin-snow Ech0 CPU amplification in i18n Middleware","severity":"high","exploited":false,"published_at":"2026-07-14T19:58:54+00:00","url":"https://junglewise.ai/threats/lin-snow-ech0-cpu-amplification-in-i18n-middleware-fefbca41"},{"cve":"CVE-2026-79664","cvss":7.4,"epss":0.0027,"slug":"cve-2026-79664-ech0-access-token-revocation-bypass-with-never-expire-tokens","title":"Ech0 access token revocation bypass with never-expire tokens","severity":"high","exploited":false,"published_at":"2026-08-25T12:16:34.37+00:00","url":"https://junglewise.ai/threats/cve-2026-79664-ech0-access-token-revocation-bypass-with-never-expire-tokens"},{"cve":"CVE-2026-79673","cvss":6.5,"epss":0.0043,"slug":"cve-2026-79673-ech0-scope-bypass-in-put-user-endpoint-via-profile-read-token","title":"Ech0 scope bypass in PUT /user endpoint via profile:read token","severity":"medium","exploited":false,"published_at":"2026-08-25T12:16:35.68+00:00","url":"https://junglewise.ai/threats/cve-2026-79673-ech0-scope-bypass-in-put-user-endpoint-via-profile-read-token"}],"generated_at":"2026-09-26T09:11:00.170868+00:00"}