—
GO-2026-5560
podinfo: cross-site scripting vulnerability in the /echo and /api/echo endpoints in github.com/stefanprodan/podinfo
Quick fix
GO-2026-5560 — github.com/stefanprodan/podinfo: upgrade to the fixed version with the command below.
go get github.com/stefanprodan/podinfo@v1.8.1-0.20260519111337-cbebb20fd485Details
podinfo: cross-site scripting vulnerability in the /echo and /api/echo endpoints in github.com/stefanprodan/podinfo
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/stefanprodan/podinfo
Introduced in:
0Fixed in: 1.8.1-0.20260519111337-cbebb20fd485Fix
go get github.com/stefanprodan/podinfo@v1.8.1-0.20260519111337-cbebb20fd485References
- https://github.com/advisories/GHSA-q23m-vm9r-5745[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2026-43644[ADVISORY]
- https://github.com/stefanprodan/podinfo/commit/cbebb20fd48588d36fc7ff3e874c128eb89692f4[FIX]
- https://github.com/stefanprodan/podinfo/pull/480[FIX]
- https://github.com/stefanprodan/podinfo/issues/474[REPORT]
- https://github.com/Niccolo10/Security-Advisories/blob/main/CVE-2026-43644/cve-2026-43644.md[WEB]
- https://github.com/stefanprodan/podinfo/releases/tag/6.12.0[WEB]
- https://www.vulncheck.com/advisories/podinfo-reflected-xss-via-echo-endpoint[WEB]