Record summary

CVE-2022-40083 has a selected CVSS score of 9.6 (critical); EIP currently links 1 Nuclei template.

Description

Labstack Echo v4.8.0 was discovered to contain an open redirect vulnerability via the Static Handler component. This vulnerability can be leveraged by attackers to cause a Server-Side Request Forgery (SSRF).

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated May 21, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

github.com/labstack/echo/v4

Browse Go / github.com/labstack/echo/v4
GitHub AdvisoryBefore 4.9.0 · Fixed in 4.9.0affected

Nuclei templates

1
ProjectDiscoveryCRITICALLabstack Echo 4.8.0 - Open RedirectCVSS 9.6

Labstack Echo 4.8.0 contains an open redirect vulnerability via the Static Handler component. An attacker can leverage this vulnerability to cause server-side request forgery, making it possible to obtain sensitive information, modify data, and/or execute unauthorized operations.

Impact

Successful exploitation of this vulnerability could lead to phishing attacks, credential theft,.

Remediation

Download and install 4.9.0, which contains a patch for this issue.

WeaknessesCWE-601
Authorspdteam
Template tagscvecve2022redirectlabstackvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
CPE: cpe:2.3:a:labstack:echo:4.8.0:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

8