Unrated severityNVD Advisory· Published Jun 27, 2026
Debian golang-github-labstack-echo: Echo is a Go web framework. Prior to 4.15.3 and 5.2.0, Echo's router and static …
CVE-2026-55677
Description
Echo is a Go web framework. Prior to 4.15.3 and 5.2.0, Echo's router and static file handler disagree on URL path decoding. The router matches routes using the raw encoded path (preserving %2F as-is), while StaticDirectoryHandler unescapes %2F to / before resolving filesystem paths. This allows an attacker to bypass route-level access controls and read static files without authorization. This vulnerability is fixed in 4.15.3 and 5.2.0.
Affected products
1Patches
Vulnerability mechanics
News mentions
0No linked articles in our index yet.