CVE-2026-79659
8.3
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
Summary
Ech0 before 4.7.3 contains a server-side request forgery vulnerability in the fetchPeerConnectInfo function that uses unvalidated HTTP requests instead of safe request methods with URL validation. Authenticated attackers can supply arbitrary URLs to access internal services and cloud metadata endpoints by triggering connection health checks or peer connection operations.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| lin-snow | Ech0 | 0 < 4.7.3 | affected |
| lin-snow | Ech0 | 4.7.3 | unaffected |
Weaknesses
- CWE-918: Server-Side Request Forgery (SSRF)
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: poc
- Automatable: no
- Technical Impact: partial
Additional References
References
- https://github.com/lin-snow/Ech0/security/advisories/GHSA-8mc6-xjpr-h98x
- https://www.vulncheck.com/advisories/ech0-before-server-side-request-forgery-via-fetchpeerconnectinfo
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.