{"schema_version":"1.7.5","id":"GHSA-m983-7426-5hrj","published":"2026-03-24T22:25:03Z","modified":"2026-03-30T20:33:40.415017Z","aliases":["CVE-2026-33638","GO-2026-4838"],"summary":"Ech0  authenticated user-list exposed data via public `/api/allusers` endpoint  ","details":"### Summary\nA public access-control flaw allows unauthenticated users to retrieve the full user list from `GET /api/allusers`. This exposes user profile metadata to anyone who can reach the application and enables remote user enumeration.\n\n### Details\nThe vulnerable route is registered as a public endpoint:\n\n- `internal/router/user.go:17`\n  - `appRouterGroup.PublicRouterGroup.GET(\"/allusers\", h.UserHandler.GetAllUsers())`\n\nHowever, the handler appears to have been intended as an authenticated endpoint:\n\n- `internal/handler/user/user.go:177-185`\n  - API annotations indicate an authentication requirement via `@Security ApiKeyAuth`\n\nThis creates a mismatch between the documented security model and the actual routing configuration. As a result, requests to `GET /api/allusers` succeed without authentication and return user records, including profile metadata such as usernames, email addresses, role-related flags, avatar values, and locale information.\n\nA negative control against another endpoint that correctly requires authentication further supports that this exposure is unintended: `GET /api/user` returns `401 Unauthorized` when no token is supplied, while `GET /api/allusers` remains publicly accessible.\n\n### Impact\n- **Type:** Access control bypass / unauthenticated data exposure\n- **Who is impacted:** Any deployment exposing the API to untrusted networks, and all users whose profile metadata is returned by the endpoint\n- **Security impact:** Enables remote user enumeration and disclosure of user profile metadata, which may facilitate account reconnaissance, phishing, and targeted credential attacks\n- **Attack preconditions:** None beyond network access to the affected API endpoint","affected":[{"package":{"name":"github.com/lin-snow/ech0","ecosystem":"Go","purl":"pkg:golang/github.com/lin-snow/ech0"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.4.8-0.20260322121226-acbf1fd71011"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-m983-7426-5hrj/GHSA-m983-7426-5hrj.json"}}],"references":[{"type":"WEB","url":"https://github.com/lin-snow/Ech0/security/advisories/GHSA-m983-7426-5hrj"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-33638"},{"type":"WEB","url":"https://github.com/lin-snow/Ech0/commit/acbf1fd71011e6b9e1e6a911128056a19862f681"},{"type":"PACKAGE","url":"https://github.com/lin-snow/Ech0"},{"type":"WEB","url":"https://github.com/lin-snow/Ech0/releases/tag/v4.2.0"}],"database_specific":{"cwe_ids":["CWE-862"],"github_reviewed":true,"github_reviewed_at":"2026-03-24T22:25:03Z","nvd_published_at":"2026-03-26T21:17:07Z","severity":"MODERATE"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"}]}