CVE-2026-35037 is a server-side request forgery (SSRF) vulnerability in Ech0, an open-source self-hosted publishing platform, affecting versions prior to 4.2.8. The GET /api/website/title endpoint fails to validate URLs passed via the website_url query parameter before making server-side HTTP requests, allowing unauthenticated attackers to access internal network services, cloud metadata endpoints, and localhost-bound services. Partial response data can be exfiltrated through HTML title tag extraction. The vulnerability carries a CVSS score of 7.2 (HIGH) with a network-based attack vector requiring no authentication or user interaction, making it easily exploitable. The attack has low complexity and results in confidentiality and integrity impacts, though availability is not affected. The broader impact scope indicates potential compromise of connected systems beyond the vulnerable application itself. There is currently no evidence of active exploitation, with the vulnerability absent from public exploit databases and CISA's Known Exploited Vulnerabilities catalog. Community attention remains minimal based on EPSS metrics. Organizations running Ech0 should prioritize updating to version 4.2.8 or later to remediate this risk, particularly for instances exposed to untrusted networks or those with access to sensitive internal services.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.2.8CPE matchmatch criteria | cpe:2.3:a:ech0:ech0:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.