Ech0 is an open-source, self-hosted publishing platform for personal idea sharing. Prior to 4.2.8, the GET /api/website/title endpoint accepts an arbitrary URL via the website_url query parameter and makes a server-side HTTP request to it without any validation of the target host or IP address. The endpoint requires no authentication. An attacker can use this to reach internal network services, cloud metadata endpoints (169.254.169.254), and localhost-bound services, with partial response data exfiltrated via the HTML <title> tag extraction This vulnerability is fixed in 4.2.8.
References
| Link | Resource |
|---|---|
| https://github.com/lin-snow/Ech0/security/advisories/GHSA-cqgf-f4x7-g6wc | Exploit Mitigation Vendor Advisory |
Configurations
History
22 Apr 2026, 18:59
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/lin-snow/Ech0/security/advisories/GHSA-cqgf-f4x7-g6wc - Exploit, Mitigation, Vendor Advisory | |
| First Time |
Ech0 ech0
Ech0 |
|
| CPE | cpe:2.3:a:ech0:ech0:*:*:*:*:*:*:*:* |
06 Apr 2026, 17:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-06 17:17
Updated : 2026-04-22 18:59
NVD link : CVE-2026-35037
Mitre link : CVE-2026-35037
CVE.ORG link : CVE-2026-35037
JSON object : View
Products Affected
ech0
- ech0
CWE
CWE-918
Server-Side Request Forgery (SSRF)
