CVE-2022-40083
Labstack Echo Open Redirect vulnerability
Record summary
CVE-2022-40083 has a selected CVSS score of 9.6 (critical); EIP currently links 1 Nuclei template.
Description
Labstack Echo v4.8.0 was discovered to contain an open redirect vulnerability via the Static Handler component. This vulnerability can be leveraged by attackers to cause a Server-Side Request Forgery (SSRF).
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated May 21, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
github.com/labstack/echo/v4Browse Go / github.com/labstack/echo/v4 | GitHub Advisory | Before 4.9.0 · Fixed in 4.9.0 | affected |
Nuclei templates
1ProjectDiscoveryCRITICALLabstack Echo 4.8.0 - Open RedirectCVSS 9.6
Labstack Echo 4.8.0 contains an open redirect vulnerability via the Static Handler component. An attacker can leverage this vulnerability to cause server-side request forgery, making it possible to obtain sensitive information, modify data, and/or execute unauthorized operations.
Impact
Successful exploitation of this vulnerability could lead to phishing attacks, credential theft,.
Remediation
Download and install 4.9.0, which contains a patch for this issue.
Source: ProjectDiscovery