github.com/labstack/echo/v5
High performance, minimalist Go web framework
Activity
- Latest release
- 1mo ago
- Total releases
- 11
- Cadence
- ~9 days
- Last 12 months
- 11
Reach
- Stars
- 32.6k
Details
- First release
- Jan 18, 2026
| Version | Released | |
|---|---|---|
v5.3.1
patch
|
v5.3.1
patch
Dependencies (3)
|
|
v5.3.0
minor
|
v5.3.0
minor
Dependencies (3)
|
|
v5.2.1
patch
|
v5.2.1
patch
Dependencies (3)
|
|
v5.2.0
minor
|
v5.2.0
minor
Dependencies (3)
|
|
v5.1.1
patch
1 CVE
CVE-2026-55677
GO-2026-6293
GHSA-vfp3-v2gw-7wfq
Aug 26, 2026
Encoded slash (%2F) bypasses route-level protection and exposes static files in github.com/labstack/echo/v4 and github.com/labstack/echo/v5 Encoded slash (%2F) bypasses route-level protection and exposes static files in github.com/labstack/echo/v4 and github.com/labstack/echo/v5 Fixed in
5.2.0
References
Updated Aug 26, 2026 · Source: OSV.dev |
v5.1.1
patch
Dependencies (3)
|
|
v5.1.0
minor
1 CVE
CVE-2026-55677
GO-2026-6293
GHSA-vfp3-v2gw-7wfq
Aug 26, 2026
Encoded slash (%2F) bypasses route-level protection and exposes static files in github.com/labstack/echo/v4 and github.com/labstack/echo/v5 Encoded slash (%2F) bypasses route-level protection and exposes static files in github.com/labstack/echo/v4 and github.com/labstack/echo/v5 Fixed in
5.2.0
References
Updated Aug 26, 2026 · Source: OSV.dev |
v5.1.0
minor
Dependencies (3)
|
|
v5.0.4
patch
1 CVE
CVE-2026-55677
GO-2026-6293
GHSA-vfp3-v2gw-7wfq
Aug 26, 2026
Encoded slash (%2F) bypasses route-level protection and exposes static files in github.com/labstack/echo/v4 and github.com/labstack/echo/v5 Encoded slash (%2F) bypasses route-level protection and exposes static files in github.com/labstack/echo/v4 and github.com/labstack/echo/v5 Fixed in
5.2.0
References
Updated Aug 26, 2026 · Source: OSV.dev |
v5.0.4
patch
Dependencies (3)
|
|
v5.0.3
patch
1 CVE
CVE-2026-55677
GO-2026-6293
GHSA-vfp3-v2gw-7wfq
Aug 26, 2026
Encoded slash (%2F) bypasses route-level protection and exposes static files in github.com/labstack/echo/v4 and github.com/labstack/echo/v5 Encoded slash (%2F) bypasses route-level protection and exposes static files in github.com/labstack/echo/v4 and github.com/labstack/echo/v5 Fixed in
5.2.0
References
Updated Aug 26, 2026 · Source: OSV.dev |
v5.0.3
patch
Dependencies (3)
|
|
v5.0.2
patch
2 CVEs
CVE-2026-55677
GO-2026-6293
GHSA-vfp3-v2gw-7wfq
Aug 26, 2026
Encoded slash (%2F) bypasses route-level protection and exposes static files in github.com/labstack/echo/v4 and github.com/labstack/echo/v5 Encoded slash (%2F) bypasses route-level protection and exposes static files in github.com/labstack/echo/v4 and github.com/labstack/echo/v5 Fixed in
5.2.0
References
Updated Aug 26, 2026 · Source: OSV.dev
CVE-2026-25766
GO-2026-4502
GHSA-pgvm-wxw2-hrv9
Feb 26, 2026
Echo has a Windows path traversal via backslash in middleware.Static default filesystem in github.com/labstack/echo/v5 Echo has a Windows path traversal via backslash in middleware.Static default filesystem in github.com/labstack/echo/v5 Fixed in
5.0.3
References Updated Feb 26, 2026 · Source: OSV.dev |
v5.0.2
patch
Dependencies (3)
|
|
v5.0.1
patch
2 CVEs
CVE-2026-55677
GO-2026-6293
GHSA-vfp3-v2gw-7wfq
Aug 26, 2026
Encoded slash (%2F) bypasses route-level protection and exposes static files in github.com/labstack/echo/v4 and github.com/labstack/echo/v5 Encoded slash (%2F) bypasses route-level protection and exposes static files in github.com/labstack/echo/v4 and github.com/labstack/echo/v5 Fixed in
5.2.0
References
Updated Aug 26, 2026 · Source: OSV.dev
CVE-2026-25766
GO-2026-4502
GHSA-pgvm-wxw2-hrv9
Feb 26, 2026
Echo has a Windows path traversal via backslash in middleware.Static default filesystem in github.com/labstack/echo/v5 Echo has a Windows path traversal via backslash in middleware.Static default filesystem in github.com/labstack/echo/v5 Fixed in
5.0.3
References Updated Feb 26, 2026 · Source: OSV.dev |
v5.0.1
patch
Dependencies (3)
|
|
v5.0.0
initial
2 CVEs
CVE-2026-55677
GO-2026-6293
GHSA-vfp3-v2gw-7wfq
Aug 26, 2026
Encoded slash (%2F) bypasses route-level protection and exposes static files in github.com/labstack/echo/v4 and github.com/labstack/echo/v5 Encoded slash (%2F) bypasses route-level protection and exposes static files in github.com/labstack/echo/v4 and github.com/labstack/echo/v5 Fixed in
5.2.0
References
Updated Aug 26, 2026 · Source: OSV.dev
CVE-2026-25766
GO-2026-4502
GHSA-pgvm-wxw2-hrv9
Feb 26, 2026
Echo has a Windows path traversal via backslash in middleware.Static default filesystem in github.com/labstack/echo/v5 Echo has a Windows path traversal via backslash in middleware.Static default filesystem in github.com/labstack/echo/v5 Fixed in
5.0.3
References Updated Feb 26, 2026 · Source: OSV.dev |
v5.0.0
initial
Dependencies (3)
|