ECHO-22f4-4100-b032

See a problem?
Import Source
https://advisory.echohq.com/osv/ECHO-22f4-4100-b032.json
JSON Data
https://api.test.osv.dev/v1/vulns/ECHO-22f4-4100-b032
Upstream
Withdrawn
2026-06-18T15:45:02Z
Published
2026-06-07T16:25:29Z
Modified
2026-07-29T18:23:39Z
Summary
Windows-only CONNECT REST curl command injection. Not applicable on Linux: the vulnerable sink is the Windows CreateProcess flat-command-line path inside '#if defined(_WIN32)', never compiled in Echo's Debian/Linux build; the Linux path passes the URL as a discrete execlp() argv element (no shell). The upstream fix (commit aca6743d) is a no-op on Linux.
Details
References

Affected packages

Echo / mariadb

Package

Name
mariadb
Purl
pkg:deb/echo/mariadb

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1:11.8.6-6+e4

Database specific

source
"https://advisory.echohq.com/osv/ECHO-22f4-4100-b032.json"