{"id":"ECHO-22f4-4100-b032","summary":"Windows-only CONNECT REST curl command injection.\nNot applicable on Linux: the vulnerable sink is the Windows CreateProcess\nflat-command-line path inside '#if defined(_WIN32)', never compiled in Echo's\nDebian/Linux build; the Linux path passes the URL as a discrete execlp() argv\nelement (no shell). The upstream fix (commit aca6743d) is a no-op on Linux.\n","modified":"2026-09-15T03:33:45.956038443Z","published":"2026-06-07T14:20:48.039Z","withdrawn":"2026-06-18T15:45:02.787Z","upstream":["CVE-2026-44170"],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2026-44170"}],"affected":[{"package":{"name":"mariadb","ecosystem":"Echo","purl":"pkg:deb/echo/mariadb"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:11.8.6-6+e4"}]}],"database_specific":{"source":"https://advisory.echohq.com/osv/ECHO-22f4-4100-b032.json"}}],"schema_version":"1.9.0"}