Skip to content

fix(deps): bump github.com/labstack/echo/v4 from 4.15.4 to 4.16.0 - #194

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/go_modules/github.com/labstack/echo/v4-4.16.0
Open

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/go_modules/github.com/labstack/echo/v4-4.16.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor

Bumps github.com/labstack/echo/v4 from 4.15.4 to 4.16.0.

Release notes

Sourced from github.com/labstack/echo/v4's releases.

v4.16.0

Security

This release fixes several security issues. Upgrading is recommended. Some fixes change behavior; read "Behavior changes to check before upgrading" below.

  • Request scheme: Context.Scheme() now uses the X-Forwarded-Proto, X-Forwarded-Protocol, X-Forwarded-Ssl and X-Url-Scheme headers only when the request comes directly from a loopback, link-local or private network address or a unix socket. Before this, any client could send X-Forwarded-Proto: https over plain HTTP and skip HTTPSRedirect. When X-Forwarded-Proto is present, only it is used (its last value), and the scheme is returned in lowercase. the new Echo#SchemeExtractor field selects the strategy: ExtractSchemeFromHeaders(...TrustOption) (default), ExtractSchemeDirect() or LegacySchemeExtractor(). The Secure middleware now sets HSTS based on Context.Scheme(). The Proxy middleware always sets X-Forwarded-Proto from Context.Scheme() and removes X-Forwarded-Ssl, X-Forwarded-Protocol and X-Url-Scheme before forwarding. GHSA-2ffq-g2xg-c22p
  • JSONP: Context.JSONP and Context.JSONPBlob accept only a callback that is empty, a JavaScript identifier or a dot-separated path of identifiers (ASCII letters, digits, _ and $). Any other callback returns a 400 Bad Request error that wraps the new ErrInvalidJSONPCallback, and nothing is written. JSONP responses now carry X-Content-Type-Options: nosniff. JSONP lets any website read the response with the user's cookies, so do not use it for data that needs authentication. GHSA-h9g5-28mm-hx3g
  • MethodOverride: a POST can no longer be overridden to GET, HEAD, OPTIONS, TRACE or CONNECT. Before this, with the MethodFromForm or MethodFromQuery getter and MethodOverride registered with Use before the CSRF middleware, _method=GET skipped the CSRF check. Register MethodOverride with Echo#Pre. GHSA-r7w9-592q-9vg4
  • Redirects: the trailing slash middlewares and the static directory redirect percent-encode control characters in the redirect path. Before this, /%09/evil.example/ redirected browsers to evil.example. GHSA-v753-g4cw-jm48
  • Static files: with the default settings, the Static middleware resolves files from the same form of the path that the router matched, so /admin%2Fsecret.txt or /%61dmin/secret.txt can no longer reach a file under a guarded /admin/* route. GHSA-375p-5qhx-8wq4 The Static middleware and StaticDirectoryHandler (used by Echo.Static, Echo.StaticFS, Group.Static and Group.StaticFS) no longer serve paths with a ., .. or empty segment, such as /assets/../admin/secret.txt, also after path unescaping. GHSA-3pmx-cf9f-34xr
  • Dependencies: update golang.org/x/text to v0.40.0 (GO-2026-5970).

Client IP address (no code change in v4)

Without Echo#IPExtractor, Context.RealIP() in v4 trusts the X-Forwarded-For and X-Real-IP headers from any client, so the rate limiter can be bypassed and the Proxy middleware forwards a spoofed X-Real-IP (GHSA-246p-cpwv-v3jq, GHSA-99jh-6h7p-pp36). Changing this default in v4 would put all clients behind a proxy into one rate-limit bucket, so v4 keeps it. Set an extractor that matches your deployment:

e.IPExtractor = echo.ExtractIPDirect()        // no proxy in front of the app
e.IPExtractor = echo.ExtractIPFromXFFHeader() // behind proxies in private networks that set X-Forwarded-For
// behind a proxy with public addresses (e.g. a CDN), also trust its ranges:
// e.IPExtractor = echo.ExtractIPFromXFFHeader(echo.TrustIPRange(cdnRange))

v5 uses the direct peer address by default since v5.1.0.

Behavior changes to check before upgrading

  • Proxies or load balancers with public IP addresses. If a proxy connects to your app from a public (or 100.64.0.0/10) address, its X-Forwarded-Proto is now ignored: HTTPSRedirect redirects in a loop and the Secure middleware stops sending HSTS. This affects, for example, Cloudflare, CloudFront and Azure Front Door connecting to a public origin, the GCP external HTTP(S) load balancer including GKE Ingress (35.191.0.0/16, 130.211.0.0/22), and networks that use 100.64.0.0/10 (such as Alibaba Cloud SLB or EKS custom networking). Trust the proxy's address ranges:
    _, gclb1, _ := net.ParseCIDR("35.191.0.0/16")
    _, gclb2, _ := net.ParseCIDR("130.211.0.0/22")
    e.SchemeExtractor = echo.ExtractSchemeFromHeaders(echo.TrustIPRange(gclb1), echo.TrustIPRange(gclb2))
    Proxies on the same host, in a private network (AWS ALB, in-cluster ingress controllers such as ingress-nginx or Traefik, most PaaS routers) or on a unix socket keep working without changes. echo.LegacySchemeExtractor() restores the old behavior but is not safe unless every request passes through a proxy that sets these headers. Serverless adapters or middleware that set RemoteAddr to the client's address also make X-Forwarded-Proto ignored (or, if they take it from a header, spoofable).
  • Trusted proxies must set X-Forwarded-Proto. A proxy on a trusted address that passes the client's X-Forwarded-Proto through (for example nginx without proxy_set_header X-Forwarded-Proto $scheme;) still lets the client choose the scheme. An invalid X-Forwarded-Proto value now results in http instead of falling back to the other scheme headers.
  • Your own tests. httptest.NewRequest sets RemoteAddr to 192.0.2.1:1234, which is not trusted, so tests that set X-Forwarded-Proto now see http. Set req.RemoteAddr = "10.0.0.1:1234" or use e.SchemeExtractor = echo.LegacySchemeExtractor() in such tests.
  • Proxy middleware headers. X-Forwarded-Ssl, X-Forwarded-Protocol and X-Url-Scheme are no longer forwarded to the upstream; X-Forwarded-Proto carries the scheme.
  • MethodOverride. Overriding a POST to GET (for example with X-HTTP-Method-Override: GET to send a long query in a POST body) is no longer done; such requests keep the POST method.
  • Static files. Paths with a double slash or dot segment (for example /assets//app.js) now return 404; in HTML5 mode the index is still served. The Static middleware no longer finds file names that the client sends with non-default escaping (for example %2C, %40 or lowercase hex like %c3%a9) unless StaticConfig.EnablePathUnescaping is set; Echo.Static has behaved this way since v4.15.4. With StaticConfig.EnablePathUnescaping or Echo#EnablePathUnescapingStaticFiles, encoded dots (%2e%2e) no longer traverse directories, but encoded slashes are still decoded, so do not combine these options with route-based access control.
  • JSONP. Context.JSONP returns an error for callbacks that are not JavaScript identifiers.

Documentation

  • Static middleware: when registered with Echo#Use it runs before route and group middleware, so route guards do not protect the files it serves.
Changelog

Sourced from github.com/labstack/echo/v4's changelog.

v4.16.0 - 2026-09-27

Security

This release fixes several security issues. Upgrading is recommended. Some fixes change behavior; read "Behavior changes to check before upgrading" below.

  • Request scheme: Context.Scheme() now uses the X-Forwarded-Proto, X-Forwarded-Protocol, X-Forwarded-Ssl and X-Url-Scheme headers only when the request comes directly from a loopback, link-local or private network address or a unix socket. Before this, any client could send X-Forwarded-Proto: https over plain HTTP and skip HTTPSRedirect. When X-Forwarded-Proto is present, only it is used (its last value), and the scheme is returned in lowercase. the new Echo#SchemeExtractor field selects the strategy: ExtractSchemeFromHeaders(...TrustOption) (default), ExtractSchemeDirect() or LegacySchemeExtractor(). The Secure middleware now sets HSTS based on Context.Scheme(). The Proxy middleware always sets X-Forwarded-Proto from Context.Scheme() and removes X-Forwarded-Ssl, X-Forwarded-Protocol and X-Url-Scheme before forwarding. GHSA-2ffq-g2xg-c22p
  • JSONP: Context.JSONP and Context.JSONPBlob accept only a callback that is empty, a JavaScript identifier or a dot-separated path of identifiers (ASCII letters, digits, _ and $). Any other callback returns a 400 Bad Request error that wraps the new ErrInvalidJSONPCallback, and nothing is written. JSONP responses now carry X-Content-Type-Options: nosniff. JSONP lets any website read the response with the user's cookies, so do not use it for data that needs authentication. GHSA-h9g5-28mm-hx3g
  • MethodOverride: a POST can no longer be overridden to GET, HEAD, OPTIONS, TRACE or CONNECT. Before this, with the MethodFromForm or MethodFromQuery getter and MethodOverride registered with Use before the CSRF middleware, _method=GET skipped the CSRF check. Register MethodOverride with Echo#Pre. GHSA-r7w9-592q-9vg4
  • Redirects: the trailing slash middlewares and the static directory redirect percent-encode control characters in the redirect path. Before this, /%09/evil.example/ redirected browsers to evil.example. GHSA-v753-g4cw-jm48
  • Static files: with the default settings, the Static middleware resolves files from the same form of the path that the router matched, so /admin%2Fsecret.txt or /%61dmin/secret.txt can no longer reach a file under a guarded /admin/* route. GHSA-375p-5qhx-8wq4 The Static middleware and StaticDirectoryHandler (used by Echo.Static, Echo.StaticFS, Group.Static and Group.StaticFS) no longer serve paths with a ., .. or empty segment, such as /assets/../admin/secret.txt, also after path unescaping. GHSA-3pmx-cf9f-34xr
  • Dependencies: update golang.org/x/text to v0.40.0 (GO-2026-5970).

Client IP address (no code change in v4)

Without Echo#IPExtractor, Context.RealIP() in v4 trusts the X-Forwarded-For and X-Real-IP headers from any client, so the rate limiter can be bypassed and the Proxy middleware forwards a spoofed X-Real-IP (GHSA-246p-cpwv-v3jq, GHSA-99jh-6h7p-pp36). Changing this default in v4 would put all clients behind a proxy into one rate-limit bucket, so v4 keeps it. Set an extractor that matches your deployment:

e.IPExtractor = echo.ExtractIPDirect()        // no proxy in front of the app
e.IPExtractor = echo.ExtractIPFromXFFHeader() // behind proxies in private networks that set X-Forwarded-For
// behind a proxy with public addresses (e.g. a CDN), also trust its ranges:
// e.IPExtractor = echo.ExtractIPFromXFFHeader(echo.TrustIPRange(cdnRange))

v5 uses the direct peer address by default since v5.1.0.

Behavior changes to check before upgrading

  • Proxies or load balancers with public IP addresses. If a proxy connects to your app from a public (or 100.64.0.0/10) address, its X-Forwarded-Proto is now ignored: HTTPSRedirect redirects in a loop and the Secure middleware stops sending HSTS. This affects, for example, Cloudflare, CloudFront and Azure Front Door connecting to a public origin, the GCP external HTTP(S) load balancer including GKE Ingress (35.191.0.0/16, 130.211.0.0/22), and networks that use 100.64.0.0/10 (such as Alibaba Cloud SLB or EKS custom networking). Trust the proxy's address ranges:
    _, gclb1, _ := net.ParseCIDR("35.191.0.0/16")
    _, gclb2, _ := net.ParseCIDR("130.211.0.0/22")
    e.SchemeExtractor = echo.ExtractSchemeFromHeaders(echo.TrustIPRange(gclb1), echo.TrustIPRange(gclb2))
    Proxies on the same host, in a private network (AWS ALB, in-cluster ingress controllers such as ingress-nginx or Traefik, most PaaS routers) or on a unix socket keep working without changes. echo.LegacySchemeExtractor() restores the old behavior but is not safe unless every request passes through a proxy that sets these headers. Serverless adapters or middleware that set RemoteAddr to the client's address also make X-Forwarded-Proto ignored (or, if they take it from a header, spoofable).
  • Trusted proxies must set X-Forwarded-Proto. A proxy on a trusted address that passes the client's X-Forwarded-Proto through (for example nginx without proxy_set_header X-Forwarded-Proto $scheme;) still lets the client choose the scheme. An invalid X-Forwarded-Proto value now results in http instead of falling back to the other scheme headers.
  • Your own tests. httptest.NewRequest sets RemoteAddr to 192.0.2.1:1234, which is not trusted, so tests that set X-Forwarded-Proto now see http. Set req.RemoteAddr = "10.0.0.1:1234" or use e.SchemeExtractor = echo.LegacySchemeExtractor() in such tests.
  • Proxy middleware headers. X-Forwarded-Ssl, X-Forwarded-Protocol and X-Url-Scheme are no longer forwarded to the upstream; X-Forwarded-Proto carries the scheme.
  • MethodOverride. Overriding a POST to GET (for example with X-HTTP-Method-Override: GET to send a long query in a POST body) is no longer done; such requests keep the POST method.
  • Static files. Paths with a double slash or dot segment (for example /assets//app.js) now return 404; in HTML5 mode the index is still served. The Static middleware no longer finds file names that the client sends with non-default escaping (for example %2C, %40 or lowercase hex like %c3%a9) unless StaticConfig.EnablePathUnescaping is set; Echo.Static has behaved this way since v4.15.4. With StaticConfig.EnablePathUnescaping or Echo#EnablePathUnescapingStaticFiles, encoded dots (%2e%2e) no longer traverse directories, but encoded slashes are still decoded, so do not combine these options with route-based access control.
  • JSONP. Context.JSONP returns an error for callbacks that are not JavaScript identifiers.

Documentation

  • Static middleware: when registered with Echo#Use it runs before route and group middleware, so route guards do not protect the files it serves.
Commits
  • e75c6c6 Merge pull request #3120 from labstack/chore/v4-bump-x-text
  • 7a49ed2 chore(deps): update golang.org/x/text to v0.40.0 (GO-2026-5970)
  • b838391 Merge commit from fork
  • 4f2f975 Fix body limit middleware state contamination with limitedReader pre-check
  • See full diff in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [github.com/labstack/echo/v4](https://github.com/labstack/echo) from 4.15.4 to 4.16.0.
- [Release notes](https://github.com/labstack/echo/releases)
- [Changelog](https://github.com/labstack/echo/blob/v4.16.0/CHANGELOG.md)
- [Commits](labstack/echo@v4.15.4...v4.16.0)

---
updated-dependencies:
- dependency-name: github.com/labstack/echo/v4
  dependency-version: 4.16.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code labels Oct 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update Go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants