CVE-2026-25766
Echo is a Go web framework. In versions 5.0.0 through 5.0.2 on Windows, Echo’s `middleware.Static` using the default filesystem allows path traversal via backslashes, enabling unauthenticated remote file read outside the static root. In `middleware/static.go`, the requested path is unescaped and normalized with `path.Clean` (URL semantics). `path.Clean` does not treat `\` as a path separator, so `..\` sequences remain in the cleaned path. The resulting path is then passed to `currentFS.Open(...)`. When the filesystem is left at the default (nil), Echo uses `defaultFS` which calls `os.Open` (`echo.go:792`). On Windows, `os.Open` treats `\` as a path separator and resolves `..\`, allowing traversal outside the static root. Version 5.0.3 fixes the issue.
EPSS 0.07% · 21.0th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| github.com | labstack/echo/v5 | 5.0.0, 5.0.0 |
| labstack | echo | 5.0.0, *, >= 5.0.0, < 5.0.3 |
Timeline
- Feb 17, 2026 CVE Published
- Feb 20, 2026 EPSS Score
- Feb 22, 2026 EPSS Score
- Feb 23, 2026 EPSS Score
- Feb 25, 2026 EPSS Score
- Feb 27, 2026 CVE Updated
- Feb 27, 2026 EPSS Score
- Feb 28, 2026 EPSS Score
- Mar 2, 2026 EPSS Score
- Mar 4, 2026 EPSS Score
- Mar 5, 2026 EPSS Score
- Mar 7, 2026 EPSS Score
References
- https://github.com/labstack/echo/security/advisories/GHSA-pgvm-wxw2-hrv9 url
- https://github.com/labstack/echo/pull/2891 url
- https://github.com/labstack/echo/commit/b1d443086ea27cf51345ec72a71e9b7e9d9ce5f1 url
- https://nvd.nist.gov/vuln/detail/CVE-2026-25766 advisory
- https://github.com/labstack/echo package
- https://pkg.go.dev/vuln/GO-2026-4502 url