← Terug naar overzicht

Ech0 versions before 4.7.3 contain a server-side request forgery (SSRF) vulnerability in the fetchPeerConnectInfo function. The function uses unvalidated HTTP requests instead of safe request methods with proper URL validation. Authenticated attackers can supply arbitrary URLs to exploit this vulnerability. The attack vector involves triggering connection health checks or peer connection operations. Exploitation allows access to internal services and cloud metadata endpoints. The vulnerability requires authentication, limiting the attack surface somewhat. Cloud environments are particularly at risk due to metadata endpoint exposure. A fix is available in version 4.7.3 and later. The issue has been documented in both GitHub Security Advisories and VulnCheck. Organizations using Ech0 in cloud or internal network environments should prioritize upgrading immediately.

Affected products

  • Ech0 before 4.7.3

Related CVE's

  • CVE-2026-79659

Categories

  • Cloud & Virtualization
  • Web Technologies