Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-35037

24
FAUCET Score

CVE-2026-35037 is a server-side request forgery (SSRF) vulnerability in Ech0, an open-source self-hosted publishing platform, affecting versions prior to 4.2.8. The GET /api/website/title endpoint fails to validate URLs passed via the website_url query parameter before making server-side HTTP requests, allowing unauthenticated attackers to access internal network services, cloud metadata endpoints, and localhost-bound services. Partial response data can be exfiltrated through HTML title tag extraction. The vulnerability carries a CVSS score of 7.2 (HIGH) with a network-based attack vector requiring no authentication or user interaction, making it easily exploitable. The attack has low complexity and results in confidentiality and integrity impacts, though availability is not affected. The broader impact scope indicates potential compromise of connected systems beyond the vulnerable application itself. There is currently no evidence of active exploitation, with the vulnerability absent from public exploit databases and CISA's Known Exploited Vulnerabilities catalog. Community attention remains minimal based on EPSS metrics. Organizations running Ech0 should prioritize updating to version 4.2.8 or later to remediate this risk, particularly for instances exposed to untrusted networks or those with access to sensitive internal services.

Impacted Technologies

VendorProductVersion(s)CPE
< 4.2.8CPE matchmatch criteria
cpe:2.3:a:ech0:ech0:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.2HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
2.7
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.29%
Probability of exploitation in next 30 days
EPSS Percentile
21.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0029 is in the 5th percentile among its peer group of 51,551 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

gopatch availablevia ghsa
Product: github.com/lin-snow/ech0Fixed in: 1.4.8-0.20260401031029-4ca56fea5ba4
github_advisoryworkaround availablevia nvd_reference
View patch

Vendor Advisories (1)

goGHSA-cqgf-f4x7-g6wchigh

Ech0: Unauthenticated SSRF in GetWebsiteTitle allows access to internal services and cloud metadata

Apr 3, 2026

References

github.com / lin-snow/Ech0/security/advisories/GHSA-cqgf-f4x7-g6wc
ExploitMitigationVendor Advisory