OVERVIEW CVE-2026-35036 affects Ech0, an open-source, self-hosted publishing platform, in versions prior to 4.2.8. The vulnerability exists in the unauthenticated GET /api/website/title endpoint, which is designed to fetch webpage titles for link previews. The endpoint accepts fully attacker-controlled URLs and performs server-side requests without proper validation controls, including no host allowlist, no SSRF filtering, and disabled SSL verification. SEVERITY The vulnerability carries a CVSS 3.1 score of 7.5 (HIGH) with a network-based attack vector requiring no privileges or user interaction. Attack complexity is low, meaning exploitation is straightforward. The primary impact is confidentiality compromise, as attackers can leverage the server to access internal resources visible from the Ech0 instance's network position, including Docker bridge addresses, VPC-internal services, and localhost endpoints. There is no integrity or availability impact. EXPLOITATION STATUS Currently, CVE-2026-35036 is not listed on CISA's Known Exploited Vulnerabilities catalog and shows no evidence of active exploitation in the wild. The EPSS probability score of 0.00044 places it well below average relative to all disclosed CVEs. No public exploit code is readily available, and community attention appears limited. Organizations running Ech0 prior to version 4.2.8 should prioritize patching as a standard maintenance task rather than as an emergency incident response.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.2.8CPE matchmatch criteria | cpe:2.3:a:ech0:ech0:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.