CVE-2026-35037 is a server-side request forgery vulnerability in Ech0, an open-source self-hosted publishing platform. In versions prior to 4.2.8, the unauthenticated GET /api/website/title endpoint accepts an arbitrary URL through the website_url query parameter and performs a server-side HTTP request to that target without validating the destination host or IP address. Because the application fetches attacker-supplied URLs on behalf of the server, an attacker can coerce the Ech0 instance into connecting to internal network resources, localhost-restricted services, and cloud instance metadata services. The endpoint also exposes partial response content by extracting and returning the HTML title element from the fetched resource, enabling limited exfiltration of data from reachable internal targets.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a compact SSRF reproduction lab and detection package for CVE-2026-35037 affecting lin-snow Ech0. It is not a full offensive exploit with post-exploitation payloads; instead, it provides a practical unauthenticated SSRF trigger and validation workflow. The repository contains 8 files: infrastructure files (.gitignore, LICENSE), lab orchestration (Dockerfile.ech0-lab and docker-compose.yml), a controlled callback artifact (evidence/index.html), a nuclei template (nuclei/CVE-2026-35037.yaml), and a shell verification script (verify-cve-2026-35037.sh). Languages present are primarily YAML, shell, Dockerfile syntax, and HTML. Because this repository includes a nuclei template, the main exploit artifact is nuclei/CVE-2026-35037.yaml. That template targets GET /api/website/title on Ech0 versions before 4.2.8 and injects website_url=http://{{interactsh-url}}/. Successful exploitation is determined by an out-of-band HTTP interaction observed by interactsh, which is a standard nuclei/OAST SSRF validation pattern. This makes the exploit network/web-based and suitable for remote unauthenticated detection of SSRF. The supporting shell script verify-cve-2026-35037.sh demonstrates the same issue manually against a local lab target. It sends a GET request to ${BASE_URL}/api/website/title with the website_url parameter set to a callback URL, defaulting to http://evidence:8080/. In the provided Docker Compose setup, the Ech0 container can reach the evidence service over the internal Docker network, and the vulnerable application returns the fetched HTML title ECH0-SSRF-CVE-2026-35037 in JSON. This confirms server-side URL fetching behavior. The Docker lab builds Ech0 from the upstream GitHub repository at tag v4.2.1 or v4.2.8, exposing port 6277 on localhost and running a Python HTTP server on port 8080 as the callback target. The README clearly documents vulnerable versus patched behavior: 4.2.1 allows unauthenticated SSRF, while 4.2.8 returns 401 Unauthorized for the same request. Overall, the repository’s purpose is to safely reproduce, verify, and scan for Ech0 SSRF using either a local evidence server or nuclei interactsh-based OAST detection.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.