Vendor
Lin-Snow vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 23 vulnerabilities in Lin-Snow: 0 in the last 7 days and 17 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-79673, was published on 25 August 2026. 1 technology has a page of its own.
- Last 7 days
- 0
- Last 90 days
- 17
- Critical, all time
- 0
- Exploited in the wild
- 0
About Lin-Snow
A developer of software components and open-source projects.
Lin-Snow technologies
Latest Lin-Snow vulnerabilities
- CVE-2026-79673: Ech0 scope bypass in PUT /user endpoint via profile:read tokenmediumCVSS 6.5EPSS 0.4%
- CVE-2026-79672: Ech0 authorization bypass in comment panel endpointsmediumCVSS 5.5EPSS 0.3%
- CVE-2026-79670: Ech0 stored cross-site scripting in file uploadmediumCVSS 4.8EPSS 0.3%
- CVE-2026-79669: Ech0 missing authorization on system log endpointsmediumCVSS 4.3EPSS 0.2%
- CVE-2026-79668: Ech0 authentication bypass in like endpointmediumCVSS 5.3EPSS 0.4%
- CVE-2026-79667: Ech0 scoped access token bypass in admin routeshighCVSS 7.6EPSS 0.3%
- CVE-2026-79666: Ech0 missing authorization on dashboard log endpointsmediumCVSS 6.5EPSS 0.4%
- CVE-2026-79665: Ech0 authorization bypass in RequireScopes middlewarehighCVSS 8.8EPSS 0.5%
- CVE-2026-79664: Ech0 access token revocation bypass with never-expire tokenshighCVSS 7.4EPSS 0.3%
- CVE-2026-79663: Ech0 stored cross-site scripting in RSS feedmediumCVSS 4.8EPSS 0.3%
- CVE-2026-79662: Ech0 OAuth redirect URI validation bypasshighCVSS 8EPSS 0.3%
- CVE-2026-79661: Ech0 unauthenticated fav_count modificationmediumCVSS 6.5EPSS 0.4%
- CVE-2026-79660: Ech0 email disclosure via public API endpointsmediumCVSS 5.3EPSS 0.4%
- CVE-2026-79659: Ech0 server-side request forgery in fetchPeerConnectInfohighCVSS 7.7EPSS 0.3%
- CVE-2026-79658: Ech0 ReDoS in Accept-Language header processing via i18n middlewarehighCVSS 7.5EPSS 0.5%
- CVE-2026-77151: lin-snow Ech0 weak cryptographic algorithm in MD5EncryptlowCVSS 3.7EPSS 0.4%
- lin-snow Ech0 CPU amplification in i18n MiddlewarehighCVSS 7.5
- lin-snow Ech0 stored XSS via SVG upload and Content-Type bypassmediumCVSS 4.8
- lin-snow Ech0 SSRF via DNS resolution bypass in webhooksmediumCVSS 5.5
- lin-snow Ech0 missing authorization in system log endpointsmediumCVSS 4.3
- lin-snow Ech0 scope bypass in PUT /user endpointmediumCVSS 6.5
- lin-snow Ech0 missing authorization in dashboard log endpointsmediumCVSS 6.5
- lin-snow Ech0 authorization bypass in privileged endpointshighCVSS 7.6
Most severe Lin-Snow vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-79665: Ech0 authorization bypass in RequireScopes middlewarehighCVSS 8.8EPSS 0.5%
- CVE-2026-79662: Ech0 OAuth redirect URI validation bypasshighCVSS 8EPSS 0.3%
- CVE-2026-79659: Ech0 server-side request forgery in fetchPeerConnectInfohighCVSS 7.7EPSS 0.3%
- CVE-2026-79667: Ech0 scoped access token bypass in admin routeshighCVSS 7.6EPSS 0.3%
- lin-snow Ech0 authorization bypass in privileged endpointshighCVSS 7.6
- CVE-2026-79658: Ech0 ReDoS in Accept-Language header processing via i18n middlewarehighCVSS 7.5EPSS 0.5%
- lin-snow Ech0 CPU amplification in i18n MiddlewarehighCVSS 7.5
- CVE-2026-79664: Ech0 access token revocation bypass with never-expire tokenshighCVSS 7.4EPSS 0.3%
- CVE-2026-79673: Ech0 scope bypass in PUT /user endpoint via profile:read tokenmediumCVSS 6.5EPSS 0.4%
- CVE-2026-79661: Ech0 unauthenticated fav_count modificationmediumCVSS 6.5EPSS 0.4%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 1 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 1 | 0 | |
| 24 Aug 2026 | 15 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/lin-snow.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Lin-Snow vulnerabilities", https://junglewise.ai/threats/vendors/lin-snow, 26 September 2026.