Ech0 < 4.2.8 - Server-Side Request Forgery
CVE-2026-35037
Verified
Description
Ech0 before 4.2.8 exposes an unauthenticated SSRF vulnerability in GET /api/website/title. The website_url query parameter is fetched server-side without validating the target host or IP address.
Severity
High
CVSS Score
7.2
Exploit Probability
1%
Affected Product
ech0
Published Date
May 20, 2026
Template Author
fineman999
CVE-2026-35037.yaml
7.2Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
CVE ID:
cve-2026-35037
CWE ID:
cwe-918