CVE Tools

Github.com/lin-snow/ech0

15 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Github.com/lin-snow/ech0, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

Github.com/lin-snow/ech0 CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Github.com/lin-snow/ech0 CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-020
2026-030
2026-047
2026-057
2026-060
2026-071
2026-080
2026-090

Latest CVEs

The 15 most recently published vulnerabilities affecting Github.com/lin-snow/ech0.

  1. GHSA-mqxv-9rm6-w8qcEch0: ParseAcceptLanguage `_` separator bypass enables ~70x CPU amplification via Accept-Language header in i18n.Middleware—
  2. GHSA-fpw6-hrg5-q5x5ech0's acess tokens with expiry=never cannot be revoked: logout panics, delete does not blacklist JTI—
  3. GHSA-p64j-f4x9-wq66Ech0's OAuth redirect URI validation ignores path component, enables exchange-code theft—
  4. GHSA-8mc6-xjpr-h98xEch0 has Server-Side Request Forgery (SSRF) via Connect Handler fetchPeerConnectInfo—
  5. GHSA-pj6q-4vq4-r8cgEch0 allows PUT /api/echo/like/:id unauthenticated: anonymous callers to modify any echo's fav_count—
  6. GHSA-rgj7-vg8v-j4wrEch0's Unauthenticated Like Endpoint Enables Arbitrary Engagement Metric Inflation—
  7. GHSA-3v85-fqvh-7rxfEch0's RSS feed renders unescaped tag names and raw-HTML markdown, stored XSS against subscribers—
  8. GHSA-rj4g-rqgh-rx9hEch0 comment model's Email field returned on public /api/comments endpoints—
  9. GHSA-69hx-63pv-f8f4Ech0 has Stored XSS via SVG Upload and Content-Type Validation Bypass in File Upload—
  10. GHSA-r2x7-427f-rq69Ech0 has SSRF via DNS Resolution Bypass in Webhook URL Validation—
  11. GHSA-w8jj-cwmc-wgq2Ech0's Missing Authorization on System Logs Allows Non-Admin Information Disclosure—
  12. GHSA-fwg7-53p4-g33cEch0 Comment Panel Endpoints Missing RequireScopes Middleware — Scoped Access Token Bypass—
  13. GHSA-hm2h-wwwh-g49xEch0 Scope Bypass: profile:read Access Token Can Change Admin Password and Escalate to Unrestricted Session—
  14. GHSA-cp79-9mwr-wr49Ech0: Missing authorization on dashboard log endpoints allows low-privilege users to access sensitive system logs—
  15. GHSA-4h9q-p5j4-xvvhEch0: Scoped admin access tokens can bypass least-privilege controls on privileged endpoints, including backup export—

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store