
🚨 CVE-2026-35037 - high 🚨 Ech0 < 4.2.8 - Server-Side Request Forgery > Ech0 before 4.2.8 exposes an unauthenticated SSRF vulnerability in GET /api/website/t... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-35037 @pdnuclei #NucleiTemplates #cve
Post summary
The tweet announces CVE‑2026‑35037, an unauthenticated SSRF vulnerability in Ech0 versions before 4.2.8, and links to a Nuclei template, but offers no exploit, patch, or active exploitation details.

