Описание
Echo: Encoded slash (%2F) bypasses route-level protection and exposes static files
Summary
Echo's router and static file handler disagree on URL path decoding. The router matches routes using the raw encoded path (preserving %2F as-is), while StaticDirectoryHandler unescapes %2F to / before resolving filesystem paths. This allows an attacker to bypass route-level access controls and read static files without authorization.
Details
Root cause 1 — router.go lines 798-802:
The router uses req.URL.RawPath for route matching when useEscapedPathForRouting is false (the default). This means /admin%2Fsecret.txt is treated as a single path segment and does NOT match the /admin/* route pattern.
Root cause 2 — echo.go lines 559-568:
StaticDirectoryHandler calls url.PathUnescape() on the path parameter before opening files. This converts %2F back to /, resolving admin/secret.txt on disk.
PoC (Screenshot)
Sample:
403:
Bypass with encoded slash:
Impact
Unauthorized static file disclosure. Applications that protect route prefixes with authentication middleware while also serving static files from a broader root are vulnerable. An attacker only needs to encode the slash (/ → %2F) in the URL to bypass all route-level protection.
Common affected pattern:
Ссылки
- https://github.com/labstack/echo/security/advisories/GHSA-vfp3-v2gw-7wfq
- https://nvd.nist.gov/vuln/detail/CVE-2026-55677
- https://github.com/labstack/echo/pull/3009
- https://github.com/labstack/echo/pull/3011
- https://github.com/labstack/echo/commit/8d1ae9d3360a71672418856d58753af25f2c3986
- https://github.com/labstack/echo/commit/c3fa2a27ff92b2b8db360de614f999ef1da24725
- https://github.com/labstack/echo/releases/tag/v4.15.3
- https://github.com/labstack/echo/releases/tag/v5.2.0
Пакеты
github.com/labstack/echo/v5
< 5.2.0
5.2.0
github.com/labstack/echo/v4
< 4.15.3
4.15.3
github.com/labstack/echo
<= 3.3.10
Отсутствует
Связанные уязвимости
Echo is a Go web framework. Prior to 4.15.3 and 5.2.0, Echo's router and static file handler disagree on URL path decoding. The router matches routes using the raw encoded path (preserving %2F as-is), while StaticDirectoryHandler unescapes %2F to / before resolving filesystem paths. This allows an attacker to bypass route-level access controls and read static files without authorization. This vulnerability is fixed in 4.15.3 and 5.2.0.
Echo is a Go web framework. Prior to 4.15.3 and 5.2.0, Echo's router and static file handler disagree on URL path decoding. The router matches routes using the raw encoded path (preserving %2F as-is), while StaticDirectoryHandler unescapes %2F to / before resolving filesystem paths. This allows an attacker to bypass route-level access controls and read static files without authorization. This vulnerability is fixed in 4.15.3 and 5.2.0.
Echo is a Go web framework. Prior to 4.15.3 and 5.2.0, Echo's router and static file handler disagree on URL path decoding. The router matches routes using the raw encoded path (preserving %2F as-is), while StaticDirectoryHandler unescapes %2F to / before resolving filesystem paths. This allows an attacker to bypass route-level access controls and read static files without authorization. This vulnerability is fixed in 4.15.3 and 5.2.0.
Echo is a Go web framework. Prior to 4.15.3 and 5.2.0, Echo's router a ...