THREAT OPS › Threat News › [NVD] CVE-2026-79671 (MEDIUM 5.5) — Ech0 before 4.4.3 contains a server-side request forgery vulnerability in the validateWebhookURL function (webhook_setting_service.go), which only validates literal IP addresses via net.ParseIP() and fails to reject hostnames that DNS-resolve to private or internal IPs (e.g., 169
[NVD] CVE-2026-79671 (MEDIUM 5.5) — Ech0 before 4.4.3 contains a server-side request forgery vulnerability in the validateWebhookURL function (webhook_setting_service.go), which only validates literal IP addresses via net.ParseIP() and fails to reject hostnames that DNS-resolve to private or internal IPs (e.g., 169
CVE-2026-79671 CVSS: 5.5 MEDIUM Published: 2026-08-25T12:16:35.390
Ech0 before 4.4.3 contains a server-side request forgery vulnerability in the validateWebhookURL function (webhook_setting_service.go), which only validates literal IP addresses via net.ParseIP() and fails to reject hostnames that DNS-resolve to private or internal IPs (e.g., 169.254.169.254.nip.io). An attacker with admin privile
MITRE ATT&CK techniques
- IP AddressesT1590.005
Indicators of compromise
- CVE-2026-79671cve
- 169.254.169.254.nip.iodomain
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-79671