Github.com/lin-snow/ech0
15 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Github.com/lin-snow/ech0, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
Github.com/lin-snow/ech0 CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 7 |
| 2026-05 | 7 |
| 2026-06 | 0 |
| 2026-07 | 1 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Latest CVEs
The 15 most recently published vulnerabilities affecting Github.com/lin-snow/ech0.
- GHSA-mqxv-9rm6-w8qcEch0: ParseAcceptLanguage `_` separator bypass enables ~70x CPU amplification via Accept-Language header in i18n.Middleware—
- GHSA-fpw6-hrg5-q5x5ech0's acess tokens with expiry=never cannot be revoked: logout panics, delete does not blacklist JTI—
- GHSA-p64j-f4x9-wq66Ech0's OAuth redirect URI validation ignores path component, enables exchange-code theft—
- GHSA-8mc6-xjpr-h98xEch0 has Server-Side Request Forgery (SSRF) via Connect Handler fetchPeerConnectInfo—
- GHSA-pj6q-4vq4-r8cgEch0 allows PUT /api/echo/like/:id unauthenticated: anonymous callers to modify any echo's fav_count—
- GHSA-rgj7-vg8v-j4wrEch0's Unauthenticated Like Endpoint Enables Arbitrary Engagement Metric Inflation—
- GHSA-3v85-fqvh-7rxfEch0's RSS feed renders unescaped tag names and raw-HTML markdown, stored XSS against subscribers—
- GHSA-rj4g-rqgh-rx9hEch0 comment model's Email field returned on public /api/comments endpoints—
- GHSA-69hx-63pv-f8f4Ech0 has Stored XSS via SVG Upload and Content-Type Validation Bypass in File Upload—
- GHSA-r2x7-427f-rq69Ech0 has SSRF via DNS Resolution Bypass in Webhook URL Validation—
- GHSA-w8jj-cwmc-wgq2Ech0's Missing Authorization on System Logs Allows Non-Admin Information Disclosure—
- GHSA-fwg7-53p4-g33cEch0 Comment Panel Endpoints Missing RequireScopes Middleware — Scoped Access Token Bypass—
- GHSA-hm2h-wwwh-g49xEch0 Scope Bypass: profile:read Access Token Can Change Admin Password and Escalate to Unrestricted Session—
- GHSA-cp79-9mwr-wr49Ech0: Missing authorization on dashboard log endpoints allows low-privilege users to access sensitive system logs—
- GHSA-4h9q-p5j4-xvvhEch0: Scoped admin access tokens can bypass least-privilege controls on privileged endpoints, including backup export—
Product grouping is registry-driven, with AI assist and human review. How it works