Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-55677

Опубликовано: 26 июн. 2026
Источник: redhat
CVSS3: 7.5

Описание

Echo is a Go web framework. Prior to 4.15.3 and 5.2.0, Echo's router and static file handler disagree on URL path decoding. The router matches routes using the raw encoded path (preserving %2F as-is), while StaticDirectoryHandler unescapes %2F to / before resolving filesystem paths. This allows an attacker to bypass route-level access controls and read static files without authorization. This vulnerability is fixed in 4.15.3 and 5.2.0.

A flaw was found in Echo, a Go web framework. An attacker can exploit a disagreement in URL path decoding between the router and the static file handler. The router processes raw encoded paths, while the static file handler unescapes encoded forward slashes. This allows an attacker to bypass route-level access controls, leading to unauthorized information disclosure by reading static files.

Отчет

This is an Important information disclosure flaw in the Echo web framework. The discrepancy in URL path decoding between the router and static file handler allows an unauthenticated attacker to bypass access controls and read arbitrary static files. This could lead to the exposure of sensitive data hosted on affected Red Hat products utilizing the Echo framework for serving static content.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/acm-grafana-rhel9Affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/acm-multicluster-observability-addon-rhel9Affected
Red Hat Ceph Storage 5rhceph/rhceph-5-dashboard-rhel8Fix deferred
Red Hat Enterprise Linux 10grafanaAffected
Red Hat Enterprise Linux 10osbuild-composerAffected
Red Hat Enterprise Linux 8grafanaNot affected
Red Hat Enterprise Linux 8osbuild-composerAffected
Red Hat Enterprise Linux 9grafanaAffected
Red Hat Enterprise Linux 9osbuild-composerAffected
Red Hat OpenShift Virtualization 4container-native-virtualization/hyperconverged-cluster-operator-rhel9Affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=2493622github.com/labstack/echo: Echo: Unauthorized Information Disclosure via URL Path Decoding Discrepancy

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 1 месяца назад

Echo is a Go web framework. Prior to 4.15.3 and 5.2.0, Echo's router and static file handler disagree on URL path decoding. The router matches routes using the raw encoded path (preserving %2F as-is), while StaticDirectoryHandler unescapes %2F to / before resolving filesystem paths. This allows an attacker to bypass route-level access controls and read static files without authorization. This vulnerability is fixed in 4.15.3 and 5.2.0.

CVSS3: 7.5
nvd
около 1 месяца назад

Echo is a Go web framework. Prior to 4.15.3 and 5.2.0, Echo's router and static file handler disagree on URL path decoding. The router matches routes using the raw encoded path (preserving %2F as-is), while StaticDirectoryHandler unescapes %2F to / before resolving filesystem paths. This allows an attacker to bypass route-level access controls and read static files without authorization. This vulnerability is fixed in 4.15.3 and 5.2.0.

CVSS3: 7.5
debian
около 1 месяца назад

Echo is a Go web framework. Prior to 4.15.3 and 5.2.0, Echo's router a ...

7.5 High

CVSS3