Echo: stdlib: security update to 1.26.9

high Tenable Cloud Security Plugin ID 474130

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- When http.Transport sends an HTTP/1 CONNECT request with a non-empty Request.Body, it writes the body
directly to the connection without framing after the request headers. If the server rejects the CONNECT
request with a non-2xx keep-alive response, Transport returns the connection to the idle pool. Because
CONNECT requests do not have a request body, the server may interpret the trailing body bytes as a
subsequent pipelined HTTP/1.1 request on the connection, leaving the pooled connection desynchronized and
causing the next caller that reuses it to read the response to the injected request. In reverse proxies
(including httputil.ReverseProxy) that forward CONNECT requests through a shared Transport, this can lead
to cross-user response poisoning. (CVE-2026-56866)

Solution

Update the stdlib library and its related packages to version 1.26.9 or later.

See Also

https://advisory.echohq.com/cve/CVE-2026-56866

Plugin Details

Severity: High

ID: 474130

Version: Revision 1.1

Type: Local

Published: 10/10/2026

Updated: 10/10/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.67

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 5.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:N/A:N

CVSS Score Source: CVE-2026-56866

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 10/10/2026

Vulnerability Publication Date: 10/8/2026

Reference Information

CVE: CVE-2026-56866