{
  "threat_severity" : "Important",
  "public_date" : "2026-06-26T16:15:55Z",
  "bugzilla" : {
    "description" : "github.com/labstack/echo: Echo: Unauthorized Information Disclosure via URL Path Decoding Discrepancy",
    "id" : "2493622",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2493622"
  },
  "cvss3" : {
    "cvss3_base_score" : "7.5",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
    "status" : "verified"
  },
  "cwe" : "CWE-22",
  "details" : [ "Echo is a Go web framework. Prior to 4.15.3 and 5.2.0, Echo's router and static file handler disagree on URL path decoding. The router matches routes using the raw encoded path (preserving %2F as-is), while StaticDirectoryHandler unescapes %2F to / before resolving filesystem paths. This allows an attacker to bypass route-level access controls and read static files without authorization. This vulnerability is fixed in 4.15.3 and 5.2.0.", "A flaw was found in Echo, a Go web framework. An attacker can exploit a disagreement in URL path decoding between the router and the static file handler. The router processes raw encoded paths, while the static file handler unescapes encoded forward slashes. This allows an attacker to bypass route-level access controls, leading to unauthorized information disclosure by reading static files." ],
  "statement" : "This is an Important information disclosure flaw in the Echo web framework. The discrepancy in URL path decoding between the router and static file handler allows an unauthenticated attacker to bypass access controls and read arbitrary static files. This could lead to the exposure of sensitive data hosted on affected Red Hat products utilizing the Echo framework for serving static content.",
  "affected_release" : [ {
    "product_name" : "Red Hat Enterprise Linux 10.0 Extended Update Support",
    "release_date" : "2026-09-03T00:00:00Z",
    "advisory" : "RHSA-2026:63134",
    "cpe" : "cpe:/o:redhat:enterprise_linux_eus:10.0",
    "package" : "osbuild-composer-0:134.1-10.el10_0"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
    "release_date" : "2026-08-31T00:00:00Z",
    "advisory" : "RHSA-2026:61585",
    "cpe" : "cpe:/a:redhat:rhel_e4s:9.2",
    "package" : "osbuild-composer-0:76.1-8.el9_2"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.6 Extended Update Support",
    "release_date" : "2026-08-20T00:00:00Z",
    "advisory" : "RHSA-2026:57541",
    "cpe" : "cpe:/a:redhat:rhel_eus:9.6",
    "package" : "osbuild-composer-0:132.2-10.el9_6"
  }, {
    "product_name" : "Cluster Observability Operator 1.5.0",
    "release_date" : "2026-08-31T00:00:00Z",
    "advisory" : "RHSA-2026:61314",
    "cpe" : "cpe:/a:redhat:cluster_observability_operator:1.5::el9",
    "package" : "cluster-observability-operator/perses-rhel9:1787593946"
  }, {
    "product_name" : "Cluster Observability Operator 1.5.0",
    "release_date" : "2026-08-31T00:00:00Z",
    "advisory" : "RHSA-2026:61314",
    "cpe" : "cpe:/a:redhat:cluster_observability_operator:1.5::el9",
    "package" : "cluster-observability-operator/perses-rhel9-operator:1787593697"
  }, {
    "product_name" : "Multicluster Global Hub 1.6.5",
    "release_date" : "2026-07-23T00:00:00Z",
    "advisory" : "RHSA-2026:44622",
    "cpe" : "cpe:/a:redhat:multicluster_globalhub:1.6::el9",
    "package" : "multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1784561376"
  }, {
    "product_name" : "Multicluster Global Hub 1.7.0",
    "release_date" : "2026-07-28T00:00:00Z",
    "advisory" : "RHSA-2026:47149",
    "cpe" : "cpe:/a:redhat:multicluster_globalhub:1.7::el9",
    "package" : "multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1784906628"
  }, {
    "product_name" : "Multicluster Global Hub 1.7.0",
    "release_date" : "2026-08-11T00:00:00Z",
    "advisory" : "RHSA-2026:53530",
    "cpe" : "cpe:/a:redhat:multicluster_globalhub:1.7::el9",
    "package" : "multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1785442872"
  }, {
    "product_name" : "Multicluster Global Hub 1.8.0",
    "release_date" : "2026-08-10T00:00:00Z",
    "advisory" : "RHSA-2026:52946",
    "cpe" : "cpe:/a:redhat:multicluster_globalhub:1.8::el9",
    "package" : "multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1785443657"
  }, {
    "product_name" : "Red Hat Advanced Cluster Management for Kubernetes 2.15",
    "release_date" : "2026-08-26T00:00:00Z",
    "advisory" : "RHSA-2026:60389",
    "cpe" : "cpe:/a:redhat:acm:2.15::el9",
    "package" : "rhacm2/acm-multicluster-observability-addon-rhel9:1787314816"
  }, {
    "product_name" : "Red Hat Advanced Cluster Management for Kubernetes 2.16",
    "release_date" : "2026-08-26T00:00:00Z",
    "advisory" : "RHSA-2026:60391",
    "cpe" : "cpe:/a:redhat:acm:2.16::el9",
    "package" : "rhacm2/acm-multicluster-observability-addon-rhel9:1787314813"
  }, {
    "product_name" : "Red Hat Advanced Cluster Management for Kubernetes 2.17",
    "release_date" : "2026-08-26T00:00:00Z",
    "advisory" : "RHSA-2026:60386",
    "cpe" : "cpe:/a:redhat:acm:2.17::el9",
    "package" : "rhacm2/acm-multicluster-observability-addon-rhel9:1787314818"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat Advanced Cluster Management for Kubernetes 2",
    "fix_state" : "Not affected",
    "package_name" : "rhacm2/acm-grafana-rhel9",
    "cpe" : "cpe:/a:redhat:acm:2"
  }, {
    "product_name" : "Red Hat Ceph Storage 5",
    "fix_state" : "Fix deferred",
    "package_name" : "rhceph/rhceph-5-dashboard-rhel8",
    "cpe" : "cpe:/a:redhat:ceph_storage:5"
  }, {
    "product_name" : "Red Hat Enterprise Linux 10",
    "fix_state" : "Not affected",
    "package_name" : "grafana",
    "cpe" : "cpe:/o:redhat:enterprise_linux:10"
  }, {
    "product_name" : "Red Hat Enterprise Linux 10",
    "fix_state" : "Affected",
    "package_name" : "osbuild-composer",
    "cpe" : "cpe:/o:redhat:enterprise_linux:10"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "fix_state" : "Not affected",
    "package_name" : "grafana",
    "cpe" : "cpe:/o:redhat:enterprise_linux:8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "fix_state" : "Affected",
    "package_name" : "osbuild-composer",
    "cpe" : "cpe:/o:redhat:enterprise_linux:8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "fix_state" : "Not affected",
    "package_name" : "grafana",
    "cpe" : "cpe:/o:redhat:enterprise_linux:9"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "fix_state" : "Affected",
    "package_name" : "osbuild-composer",
    "cpe" : "cpe:/o:redhat:enterprise_linux:9"
  }, {
    "product_name" : "Red Hat OpenShift Virtualization 4",
    "fix_state" : "Not affected",
    "package_name" : "container-native-virtualization/hyperconverged-cluster-operator-rhel9",
    "cpe" : "cpe:/a:redhat:container_native_virtualization:4"
  }, {
    "product_name" : "Red Hat OpenShift Virtualization 4",
    "fix_state" : "Not affected",
    "package_name" : "container-native-virtualization/hyperconverged-cluster-webhook-rhel9",
    "cpe" : "cpe:/a:redhat:container_native_virtualization:4"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2026-55677\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-55677\nhttps://github.com/labstack/echo/security/advisories/GHSA-vfp3-v2gw-7wfq" ],
  "name" : "CVE-2026-55677",
  "mitigation" : {
    "value" : "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
    "lang" : "en:us"
  },
  "csaw" : false
}