CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2026-79659: Ech0 0 to before 4.7.3

CVE-2026-79659. CVSS 3.1 base score 7.7 (HIGH, Vendor/CNA). EPSS 0.00264 (percentile 0.16643), scored 2026-10-06.

Affected technology

Ech0 · 0 to before 4.7.3
lin-snow

Description’s affected range: before 4.7.3

Component: Not specified by the source
Function: that

Attack conditions (Vendor/CNA, CVSS 4.0): Network (remote) · Low privileges required · No user interaction required

What an attacker can do

Authenticated attackers can supply arbitrary URLs to access internal services and cloud metadata endpoints by triggering connection health checks or peer connection operations. Vendor/CNA’s CVSS 4.0 assessment (base score 8.3/10) rates confidentiality impact as high; integrity and availability impact as none.

Published

CWE
CWE-918
CCR priority
30.9 /100 (P4)
CVSS 3.1
7.7 /10 · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N · Vendor/CNA
EPSS
0.00264 · percentile 0.16719 · 2026-10-08
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-79659.html