GO-2026-6293
Dashboard / Vulnerabilities / GO-2026-6293
GO-2026-6293
Summary: Encoded slash (%2F) bypasses route-level protection and exposes static files in github.com/labstack/echo/v4 and github.com/labstack/echo/v5
Details: Encoded slash (%2F) bypasses route-level protection and exposes static files in github.com/labstack/echo/v4 and github.com/labstack/echo/v5
References: https://github.com/labstack/echo/security/advisories/GHSA-vfp3-v2gw-7wfq, https://nvd.nist.gov/vuln/detail/CVE-2026-55677, https://github.com/labstack/echo/commit/8d1ae9d3360a71672418856d58753af25f2c3986, https://github.com/labstack/echo/commit/c3fa2a27ff92b2b8db360de614f999ef1da24725, https://github.com/labstack/echo/pull/3009, https://github.com/labstack/echo/pull/3011, https://github.com/labstack/echo/releases/tag/v4.15.3, https://github.com/labstack/echo/releases/tag/v5.2.0
Affected packages
Package
Name: github.com/labstack/echo/v4
Purl: pkg:golang/github.com/labstack/echo/v4
Affected ranges
Type: SEMVER
Events:
