Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 25 Aug 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Lin-snow
Lin-snow ech0 |
|
| Vendors & Products |
Lin-snow
Lin-snow ech0 |
Tue, 25 Aug 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Ech0 through 4.5.6 registers the PUT /api/echo/like/:id endpoint on the public router group without authentication or rate limiting. Unauthenticated attackers can increment the fav_count counter of any echo (including private echoes) by supplying its UUID, which can be harvested from the public GET /api/echo/page feed. Repeated requests are accepted without deduplication, each triggering a database write and a four-key cache invalidation, allowing attackers to inflate popularity metrics and amplify load on the database and cache. Fixed in 4.7.3. | |
| Title | Ech0 before 4.7.3 Unauthenticated fav_count Modification | |
| First Time appeared |
Ech0
Ech0 ech0 |
|
| Weaknesses | CWE-770 | |
| CPEs | cpe:2.3:a:ech0:ech0:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Ech0
Ech0 ech0 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-25T11:33:25.369Z
Reserved: 2026-08-25T11:09:11.171Z
Link: CVE-2026-79661
No data.
Status : Received
Published: 2026-08-25T12:16:29.870
Modified: 2026-08-25T12:16:29.870
Link: CVE-2026-79661
No data.
OpenCVE Enrichment
Updated: 2026-08-25T13:30:17Z
-
CWE-770
Allocation of Resources Without Limits or Throttling