VYPR
Medium severity5.5OSV Advisory· Published Aug 25, 2026· Updated Aug 31, 2026

CVE-2026-79671

CVE-2026-79671

Description

Ech0 before 4.4.3 contains a server-side request forgery vulnerability in the validateWebhookURL function (webhook_setting_service.go), which only validates literal IP addresses via net.ParseIP() and fails to reject hostnames that DNS-resolve to private or internal IPs (e.g., 169.254.169.254.nip.io). An attacker with admin privileges can create a webhook with such a hostname to bypass validation and cause the server to make requests to internal services, cloud metadata endpoints, and private network resources. The issue is fixed in 4.4.3.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Lin Snow/Ech0OSV2 versions
    v4.4.2, v4.4.1, v4.4.0, …+ 1 more
    • (no CPE)range: v4.4.2, v4.4.1, v4.4.0, …
    • (no CPE)range: <4.4.3

Patches

Vulnerability mechanics

References

2

News mentions

1