Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-m983-7426-5hrj | Ech0 authenticated user-list exposed data via public `/api/allusers` endpoint |
Wed, 01 Apr 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ech0
Ech0 ech0 |
|
| CPEs | cpe:2.3:a:ech0:ech0:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Ech0
Ech0 ech0 |
Sat, 28 Mar 2026 03:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 27 Mar 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Lin-snow
Lin-snow ech0 |
|
| Vendors & Products |
Lin-snow
Lin-snow ech0 |
Thu, 26 Mar 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Ech0 is an open-source, self-hosted publishing platform for personal idea sharing. Prior to version 4.2.0, `GET /api/allusers` is mounted as a public endpoint and returns user records without authentication. This allows remote unauthenticated user enumeration and exposure of user profile metadata. A fix is available in v4.2.0. | |
| Title | Ech0 authenticated user-list exposed data via public `/api/allusers` endpoint | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-27T20:19:07.459Z
Reserved: 2026-03-23T14:24:11.619Z
Link: CVE-2026-33638
Updated: 2026-03-27T20:18:44.481Z
Status : Analyzed
Published: 2026-03-26T21:17:07.467
Modified: 2026-03-31T21:09:16.307
Link: CVE-2026-33638
No data.
OpenCVE Enrichment
Updated: 2026-04-02T07:56:19Z
Github GHSA