High severity7.5NVD Advisory· Published Jun 26, 2026· Updated Jun 26, 2026
CVE-2026-55677
CVE-2026-55677
Description
Echo is a Go web framework. Prior to 4.15.3 and 5.2.0, Echo's router and static file handler disagree on URL path decoding. The router matches routes using the raw encoded path (preserving %2F as-is), while StaticDirectoryHandler unescapes %2F to / before resolving filesystem paths. This allows an attacker to bypass route-level access controls and read static files without authorization. This vulnerability is fixed in 4.15.3 and 5.2.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/labstack/echo/v5Go | < 5.2.0 | 5.2.0 |
github.com/labstack/echo/v4Go | < 4.15.3 | 4.15.3 |
github.com/labstack/echoGo | <= 3.3.10 | — |
Affected products
17- osv-coords16 versionspkg:apk/chainguard/kube-metrics-adapterpkg:apk/chainguard/falcosidekick-ui-fipspkg:apk/wolfi/temporal-ui-serverpkg:apk/chainguard/falcosidekick-uipkg:apk/chainguard/temporal-ui-serverpkg:rpm/opensuse/govulncheck-vulndb&distro=openSUSE%20Leap%2016.0pkg:apk/chainguard/kube-metrics-adapter-fipspkg:apk/chainguard/temporal-fipspkg:rpm/almalinux/osbuild-composerpkg:rpm/almalinux/osbuild-composer-corepkg:rpm/almalinux/osbuild-composer-workerpkg:apk/chainguard/listmonkpkg:apk/chainguard/temporalpkg:apk/chainguard/temporal-ui-server-fipspkg:apk/wolfi/kube-metrics-adapterpkg:apk/wolfi/temporal
< 0.2.9-r18+ 15 more
- (no CPE)range: < 0.2.9-r18
- (no CPE)range: < 2.3.1-r3
- (no CPE)range: < 2.53.3-r3
- (no CPE)range: < 2.3.1-r3
- (no CPE)range: < 2.53.3-r3
- (no CPE)range: < 0.0.20260827T195228-160000.1.1
- (no CPE)range: < 0.2.9-r14
- (no CPE)range: < 1.8.2-r2
- (no CPE)range: < 101.5-3.el8_10.alma.1
- (no CPE)range: < 101.5-3.el8_10.alma.1
- (no CPE)range: < 101.5-3.el8_10.alma.1
- (no CPE)range: < 6.2.0-r8
- (no CPE)range: < 1.8.2-r4
- (no CPE)range: < 2.53.3-r1
- (no CPE)range: < 0.2.9-r18
- (no CPE)range: < 1.8.2-r4
- Range: <5.2.0
Patches
Vulnerability mechanics
References
9- github.com/advisories/GHSA-vfp3-v2gw-7wfqghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-55677ghsaADVISORY
- github.com/labstack/echo/commit/8d1ae9d3360a71672418856d58753af25f2c3986ghsaWEB
- github.com/labstack/echo/commit/c3fa2a27ff92b2b8db360de614f999ef1da24725ghsaWEB
- github.com/labstack/echo/pull/3009ghsaWEB
- github.com/labstack/echo/pull/3011ghsaWEB
- github.com/labstack/echo/releases/tag/v4.15.3ghsaWEB
- github.com/labstack/echo/releases/tag/v5.2.0ghsaWEB
- github.com/labstack/echo/security/advisories/GHSA-vfp3-v2gw-7wfqnvdWEB
News mentions
0No linked articles in our index yet.