Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 8

Количество 8

ubuntu логотип

CVE-2026-55677

3 месяца назад

Echo is a Go web framework. Prior to 4.15.3 and 5.2.0, Echo's router and static file handler disagree on URL path decoding. The router matches routes using the raw encoded path (preserving %2F as-is), while StaticDirectoryHandler unescapes %2F to / before resolving filesystem paths. This allows an attacker to bypass route-level access controls and read static files without authorization. This vulnerability is fixed in 4.15.3 and 5.2.0.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2026-55677

3 месяца назад

Echo is a Go web framework. Prior to 4.15.3 and 5.2.0, Echo's router and static file handler disagree on URL path decoding. The router matches routes using the raw encoded path (preserving %2F as-is), while StaticDirectoryHandler unescapes %2F to / before resolving filesystem paths. This allows an attacker to bypass route-level access controls and read static files without authorization. This vulnerability is fixed in 4.15.3 and 5.2.0.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-55677

3 месяца назад

Echo is a Go web framework. Prior to 4.15.3 and 5.2.0, Echo's router and static file handler disagree on URL path decoding. The router matches routes using the raw encoded path (preserving %2F as-is), while StaticDirectoryHandler unescapes %2F to / before resolving filesystem paths. This allows an attacker to bypass route-level access controls and read static files without authorization. This vulnerability is fixed in 4.15.3 and 5.2.0.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2026-55677

3 месяца назад

Echo is a Go web framework. Prior to 4.15.3 and 5.2.0, Echo's router a ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-vfp3-v2gw-7wfq

24 дня назад

Echo: Encoded slash (%2F) bypasses route-level protection and exposes static files

CVSS3: 7.5
EPSS: Низкий
rocky логотип

RLSA-2026:67148

4 дня назад

Important: osbuild-composer security update

EPSS: Низкий
rocky логотип

RLSA-2026:66432

8 дней назад

Important: osbuild-composer security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-66432-0

5 дней назад

ELSA-2026-66432-0: osbuild-composer security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-55677

Echo is a Go web framework. Prior to 4.15.3 and 5.2.0, Echo's router and static file handler disagree on URL path decoding. The router matches routes using the raw encoded path (preserving %2F as-is), while StaticDirectoryHandler unescapes %2F to / before resolving filesystem paths. This allows an attacker to bypass route-level access controls and read static files without authorization. This vulnerability is fixed in 4.15.3 and 5.2.0.

CVSS3: 7.5
0%
Низкий
3 месяца назад
redhat логотип
CVE-2026-55677

Echo is a Go web framework. Prior to 4.15.3 and 5.2.0, Echo's router and static file handler disagree on URL path decoding. The router matches routes using the raw encoded path (preserving %2F as-is), while StaticDirectoryHandler unescapes %2F to / before resolving filesystem paths. This allows an attacker to bypass route-level access controls and read static files without authorization. This vulnerability is fixed in 4.15.3 and 5.2.0.

CVSS3: 7.5
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-55677

Echo is a Go web framework. Prior to 4.15.3 and 5.2.0, Echo's router and static file handler disagree on URL path decoding. The router matches routes using the raw encoded path (preserving %2F as-is), while StaticDirectoryHandler unescapes %2F to / before resolving filesystem paths. This allows an attacker to bypass route-level access controls and read static files without authorization. This vulnerability is fixed in 4.15.3 and 5.2.0.

CVSS3: 7.5
0%
Низкий
3 месяца назад
debian логотип
CVE-2026-55677

Echo is a Go web framework. Prior to 4.15.3 and 5.2.0, Echo's router a ...

CVSS3: 7.5
0%
Низкий
3 месяца назад
github логотип
GHSA-vfp3-v2gw-7wfq

Echo: Encoded slash (%2F) bypasses route-level protection and exposes static files

CVSS3: 7.5
0%
Низкий
24 дня назад
rocky логотип
RLSA-2026:67148

Important: osbuild-composer security update

4 дня назад
rocky логотип
RLSA-2026:66432

Important: osbuild-composer security update

8 дней назад
oracle-oval логотип
ELSA-2026-66432-0

ELSA-2026-66432-0: osbuild-composer security update (IMPORTANT)

5 дней назад

Уязвимостей на страницу