CVE-2026-35037

Ech0 is an open-source, self-hosted publishing platform for personal idea sharing. Prior to 4.2.8, the GET /api/website/title endpoint accepts an arbitrary URL via the website_url query parameter and makes a server-side HTTP request to it without any validation of the target host or IP address. The endpoint requires no authentication. An attacker can use this to reach internal network services, cloud metadata endpoints (169.254.169.254), and localhost-bound services, with partial response data exfiltrated via the HTML <title> tag extraction This vulnerability is fixed in 4.2.8.
References
Link Resource
https://github.com/lin-snow/Ech0/security/advisories/GHSA-cqgf-f4x7-g6wc Exploit Mitigation Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:ech0:ech0:*:*:*:*:*:*:*:*

History

22 Apr 2026, 18:59

Type Values Removed Values Added
References () https://github.com/lin-snow/Ech0/security/advisories/GHSA-cqgf-f4x7-g6wc - () https://github.com/lin-snow/Ech0/security/advisories/GHSA-cqgf-f4x7-g6wc - Exploit, Mitigation, Vendor Advisory
First Time Ech0 ech0
Ech0
CPE cpe:2.3:a:ech0:ech0:*:*:*:*:*:*:*:*

06 Apr 2026, 17:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-06 17:17

Updated : 2026-04-22 18:59


NVD link : CVE-2026-35037

Mitre link : CVE-2026-35037

CVE.ORG link : CVE-2026-35037


JSON object : View

Products Affected

ech0

  • ech0
CWE
CWE-918

Server-Side Request Forgery (SSRF)