EXECUTIVE SUMMARY:
A high-severity vulnerability, CVE-2026-55677, with a CVSS score of 7.5, exists in Echo's router and static file handler. This flaw occurs when the router matches routes using the raw encoded path while the StaticDirectoryHandler unescapes %2F to / before resolving filesystem paths. An attacker can exploit this vulnerability by encoding the slash in the URL, bypassing all route-level protection and exposing sensitive information. The flaw allows unauthorized static file disclosure, impacting applications that protect route prefixes with authentication middleware while also serving static files from a broader root.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
A high-severity vulnerability, CVE-2026-55677, with a CVSS score of 7.5, exists in Echo's router and static file handler. This flaw occurs when the router matches routes using the raw encoded path while the StaticDirectoryHandler unescapes %2F to / before resolving filesystem paths. An attacker can exploit this vulnerability by encoding the slash in the URL, bypassing all route-level protection and exposing sensitive information. The flaw allows unauthorized static file disclosure, impacting applications that protect route prefixes with authentication middleware while also serving static files from a broader root.[emaillocker id="1283"]
RECOMMENDATIONS:
REFERENCES:
The following reports contain further technical details:
https://github.com/advisories/GHSA-vfp3-v2gw-7wfq