A AegiFlow
HIGHCVSS 7.5EPSS 0.4%

CVE-2026-55677

Echo: Encoded slash (%2F) bypasses route-level protection and exposes static files

Published
2026-08-25
Modified
2026-08-25
EPSS percentile
36%
Aliases
GHSA-vfp3-v2gw-7wfq
Sources
github-advisory

Summary

### Summary Echo's router and static file handler disagree on URL path decoding. The router matches routes using the raw encoded path (preserving `%2F` as-is), while `StaticDirectoryHandler` unescapes `%2F` to `/` before resolving filesystem paths. This allows an attacker to bypass route-level access controls and read static files without authorization. ### Details **Root cause 1 — `router.go` lines 798-802:** The router uses `req.URL.RawPath` for route matching when `useEscapedPathForRouting` is false (the default). This means `/admin%2Fsecret.txt` is treated as a single path segment and does NOT match the `/admin/*` route pattern. ```go if !r.useEscapedPathForRouting && req.URL.RawPath != "" { path = req.URL.RawPath } ``` **Root cause 2 — `echo.go` lines 559-568:** `StaticDirectoryHandler` calls `url.PathUnescape()` on the path parameter before opening files. This converts `%2F` back to `/`, resolving `admin/secret.txt` on disk. ```go if !disablePathUnescaping { tmpPath, err := url.PathUnescape(p) p = tmpPath } name := filepath.ToSlash(filepath.Clean(strings.TrimPrefix(p, "/"))) ``` ### PoC (Screenshot) Sample: 403: Bypass with encoded slash: ### Impact Unauthorized static file disclosure. Applications that protect route prefixes with authentication middleware while also serving static files from a broader root are vulnerable. An attacker only needs to encode the slash (`/` → `%2F`) in the URL to bypass all route-level protection. Common affected pattern: ```go adminGroup := e.Group("/admin", authMiddleware) e.StaticFS("/", os.DirFS("public")) ```

Affected packages

EcosystemPackageAffected versionsFixed versions
Gogithub.com/labstack/echo
Gogithub.com/labstack/echo/v44.15.3
Gogithub.com/labstack/echo/v55.2.0

Remediation: No patched version is listed by GitHub.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.