CVE-2026-79659

Ech0 before 4.7.3 contains a server-side request forgery vulnerability in the fetchPeerConnectInfo function that uses unvalidated HTTP requests instead of safe request methods with URL validation. Authenticated attackers can supply arbitrary URLs to access internal services and cloud metadata endpoints by triggering connection health checks or peer connection operations.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-25 12:16

Updated : 2026-08-25 13:19


NVD link : CVE-2026-79659

Mitre link : CVE-2026-79659

CVE.ORG link : CVE-2026-79659


JSON object : View

Products Affected

No product.

CWE
CWE-918

Server-Side Request Forgery (SSRF)