PackageTrack

Go modules

github.com/labstack/echo/v4

v4.15.4labstack/echo

Release timeline

511 releases since 2019
20192026

One column per quarter.

Releases

  1. v4.15.5-0.20260706201043-4f2f975ddadd6 Jul 2026pre-release

    Nothing published for this version

  2. v4.15.415 Jun 2026
    Release notes2 sources agree

    Security

    Fixes GHSA-vfp3-v2gw-7wfq: an encoded path separator (%2F or %5C) in a static file URL could bypass route-level middleware (e.g. authentication on a sibling route) and disclose static files. Both StaticDirectoryHandler (used by Static/StaticFS) and the Static middleware are affected. Backport of the v5 fix (#3016, released in v5.2.1). Thanks to @a-tt-om and @oran-gugu for reporting.


    Make serving static file releated methods and middleware not unescape path by default - so how the way Router interprets paths and Static methods/middleware is consistent.

    Given following situation:

    // 0.
    // given folder structure:
    // private.txt
    // public/
    // public/index.html
    // public/text.txt
    // public/admin/private.txt
    
    // 1. share `public/` folder contents from the server root. This folder actually contains subfolder `admin` which
    // contents we want to forbid from downloading
    e.Static("/", "public")
    
    // 2. naively assume that everything under /admin folder is now forbidden
    e.GET("/admin/*", func(c *Context) error {
        return ErrForbidden
    })

    Then requests to /admin%2fprivate.txt would not be matched to GET /admin/* route (routing does not look unescaped path) and static file serving will use unescaped path to serve the file.

    Note: this way of "guarding" subfolders will never work for for paths like /assets/../admin%2fprivate.txt which will path.Clean("/assets/../admin%2fprivate.txt") to /admin/private.txt and are servable if static file serving is configured to unescape paths.

    If you want to guard routes - use middlewares on Static* methods and before Static middleware.

    Breaking change / migration: If you serve files whose names contain URL-encoded characters (e.g., /hello%20world.txthello world.txt), you must now opt in:

    	e := echo.New()
    	e.EnablePathUnescapingStaticFiles = true  // <-- enable old behavior
    	e.Static("/", "public")

    for static middleware

    	e.Use(middleware.StaticWithConfig(middleware.StaticConfig{
    		EnablePathUnescaping: true, // <-- enable old behavior
    	}))

    Full Changelog: v4.15.3...v4.15.4

    Open source →
    Additional notes

    v4.15.4

    Compare

    Choose a tag to compare

    Open source →
  3. v4.15.314 Jun 2026
    Release notes2 sources agree

    Security

    • fix(static): reject encoded path separators that bypass route-level middleware by @vishr in #3011

    Fixes GHSA-vfp3-v2gw-7wfq: an encoded path separator (%2F or %5C) in a static file URL could bypass route-level middleware (e.g. authentication on a sibling route) and disclose static files. Both StaticDirectoryHandler (used by Static/StaticFS) and the Static middleware are affected. Backport of the v5 fix (#3009, released in v5.2.0). Thanks to @a-tt-om and @oran-gugu for reporting.

    Full Changelog: v4.15.2...v4.15.3

    Open source →
    Additional notes

    v4.15.3 - Static encoded-separator route bypass fix (GHSA-vfp3-v2gw-7wfq)

    Compare

    Choose a tag to compare

    Open source →
  4. v4.15.3-0.20260614161552-c3fa2a27ff9214 Jun 2026pre-release

    Nothing published for this version

  5. v4.15.21 May 2026
    Release notes

    Security

    • Context.Scheme() should validate values taken from header by @aldas in #2962

    Thanks to @shblue21 for reporting this issue.

    Full Changelog: v4.15.1...v4.15.2

    Open source →
    Additional notes

    v4.15.2 - Context.Scheme() header validation

    Compare

    Choose a tag to compare

    Open source →
    Additional notes

    Security

    • Context.Scheme() should validate values taken from header by @aldas in https://github.com/labstack/echo/pull/2962

    Thanks to @shblue21 for reporting this issue.

    Open source →
  6. v4.15.122 Feb 2026
    Release notes2 sources agree

    What's Changed

    • CSRF: support older token-based CSRF protection handler that want to render token into template by @aldas in #2905

    Full Changelog: v4.15.0...v4.15.1

    Open source →
    Additional notes

    v4.15.1

    Compare

    Choose a tag to compare

    Open source →
  7. v4.15.01 Jan 2026
    Release notes2 sources agree

    Security

    NB: If your application relies on cross-origin or same-site (same subdomain) requests do not blindly push this version to production

    The CSRF middleware now supports the Sec-Fetch-Site header as a modern, defense-in-depth approach to CSRF protection, implementing the OWASP-recommended Fetch Metadata API alongside the traditional token-based mechanism.

    How it works:

    Modern browsers automatically send the Sec-Fetch-Site header with all requests, indicating the relationship between the request origin and the target. The middleware uses this to make security decisions:

    • same-origin or none: Requests are allowed (exact origin match or direct user navigation)
    • same-site: Falls back to token validation (e.g., subdomain to main domain)
    • cross-site: Blocked by default with 403 error for unsafe methods (POST, PUT, DELETE, PATCH)

    For browsers that don't send this header (older browsers), the middleware seamlessly falls back to traditional token-based CSRF protection.

    New Configuration Options:

    • TrustedOrigins []string: Allowlist specific origins for cross-site requests (useful for OAuth callbacks, webhooks)
    • AllowSecFetchSiteFunc func(echo.Context) (bool, error): Custom logic for same-site/cross-site request validation

    Example:

    e.Use(middleware.CSRFWithConfig(middleware.CSRFConfig{
        // Allow OAuth callbacks from trusted provider
        TrustedOrigins: []string{"https://oauth-provider.com"},
    
        // Custom validation for same-site requests
        AllowSecFetchSiteFunc: func(c echo.Context) (bool, error) {
            // Your custom authorization logic here
            return validateCustomAuth(c), nil
            // return true, err  // blocks request with error
            // return true, nil  // allows CSRF request through
            // return false, nil // falls back to legacy token logic
        },
    }))
    

    PR: https://github.com/labstack/echo/pull/2858

    Type-Safe Generic Parameter Binding

    • Added generic functions for type-safe parameter extraction and context access by @aldas in https://github.com/labstack/echo/pull/2856

      Echo now provides generic functions for extracting path, query, and form parameters with automatic type conversion, eliminating manual string parsing and type assertions.

      New Functions:

      • Path parameters: PathParam[T], PathParamOr[T]
      • Query parameters: QueryParam[T], QueryParamOr[T], QueryParams[T], QueryParamsOr[T]
      • Form values: FormParam[T], FormParamOr[T], FormParams[T], FormParamsOr[T]
      • Context store: ContextGet[T], ContextGetOr[T]

      Supported Types: Primitives (bool, string, int/uint variants, float32/float64), time.Duration, time.Time (with custom layouts and Unix timestamp support), and custom types implementing BindUnmarshaler, TextUnmarshaler, or JSONUnmarshaler.

      Example:

      // Before: Manual parsing
      idStr := c.Param("id")
      id, err := strconv.Atoi(idStr)
      
      // After: Type-safe with automatic parsing
      id, err := echo.PathParam[int](c, "id")
      
      // With default values
      page, err := echo.QueryParamOr[int](c, "page", 1)
      limit, err := echo.QueryParamOr[int](c, "limit", 20)
      
      // Type-safe context access (no more panics from type assertions)
      user, err := echo.ContextGet[*User](c, "user")
      

    PR: https://github.com/labstack/echo/pull/2856

    DEPRECATION NOTICE Timeout Middleware Deprecated - Use ContextTimeout Instead

    The middleware.Timeout middleware has been deprecated due to fundamental architectural issues that cause data races. Use middleware.ContextTimeout or middleware.ContextTimeoutWithConfig instead.

    Why is this being deprecated?

    The Timeout middleware manipulates response writers across goroutine boundaries, which causes data races that cannot be reliably fixed without a complete architectural redesign. The middleware:

    • Swaps the response writer using http.TimeoutHandler
    • Must be the first middleware in the chain (fragile constraint)
    • Can cause races with other middleware (Logger, metrics, custom middleware)
    • Has been the source of multiple race condition fixes over the years

    What should you use instead?

    The ContextTimeout middleware (available since v4.12.0) provides timeout functionality using Go's standard context mechanism. It is:

    • Race-free by design
    • Can be placed anywhere in the middleware chain
    • Simpler and more maintainable
    • Compatible with all other middleware

    Migration Guide:

    // Before (deprecated):
    e.Use(middleware.Timeout())
    
    // After (recommended):
    e.Use(middleware.ContextTimeout(30 * time.Second))
    

    Important Behavioral Differences:

    1. Handler cooperation required: With ContextTimeout, your handlers must check context.Done() for cooperative cancellation. The old Timeout middleware would send a 503 response regardless of handler cooperation, but had data race issues.

    2. Error handling: ContextTimeout returns errors through the standard error handling flow. Handlers that receive context.DeadlineExceeded should handle it appropriately:

    e.GET("/long-task", func(c echo.Context) error {
        ctx := c.Request().Context()
    
        // Example: database query with context
        result, err := db.QueryContext(ctx, "SELECT * FROM large_table")
        if err != nil {
            if errors.Is(err, context.DeadlineExceeded) {
                // Handle timeout
                return echo.NewHTTPError(http.StatusServiceUnavailable, "Request timeout")
            }
            return err
        }
    
        return c.JSON(http.StatusOK, result)
    })
    
    1. Background tasks: For long-running background tasks, use goroutines with context:
    e.GET("/async-task", func(c echo.Context) error {
        ctx := c.Request().Context()
    
        resultCh := make(chan Result, 1)
        errCh := make(chan error, 1)
    
        go func() {
            result, err := performLongTask(ctx)
            if err != nil {
                errCh <- err
                return
            }
            resultCh <- result
        }()
    
        select {
        case result := <-resultCh:
            return c.JSON(http.StatusOK, result)
        case err := <-errCh:
            return err
        case <-ctx.Done():
            return echo.NewHTTPError(http.StatusServiceUnavailable, "Request timeout")
        }
    })
    

    Enhancements

    • Fixes by @aldas in https://github.com/labstack/echo/pull/2852
    • Generic functions by @aldas in https://github.com/labstack/echo/pull/2856
    • CRSF with Sec-Fetch-Site checks by @aldas in https://github.com/labstack/echo/pull/2858
    Open source →
  8. v4.14.1-0.20251228212131-4dcb9b44f0a128 Dec 2025pre-release

    Nothing published for this version

  9. v4.14.1-0.20251212111053-321530d2c2d112 Dec 2025pre-release

    Nothing published for this version

  10. v4.14.011 Dec 2025
    Release notes2 sources agree

    middleware.Logger has been deprecated. For request logging, use middleware.RequestLogger or middleware.RequestLoggerWithConfig.

    middleware.RequestLogger replaces middleware.Logger, offering comparable configuration while relying on the Go standard library’s new slog logger.

    The previous default output format was JSON. The new default follows the standard slog logger settings. To continue emitting request logs in JSON, configure slog accordingly:

    slog.SetDefault(slog.New(slog.NewJSONHandler(os.Stdout, nil)))
    e.Use(middleware.RequestLogger())
    

    Security

    • Logger middleware json string escaping and deprecation by @aldas in https://github.com/labstack/echo/pull/2849

    Enhancements

    • Update deps by @aldas in https://github.com/labstack/echo/pull/2807
    • refactor to use reflect.TypeFor by @cuiweixie in https://github.com/labstack/echo/pull/2812
    • Use Go 1.25 in CI by @aldas in https://github.com/labstack/echo/pull/2810
    • Modernize context.go by replacing interface{} with any by @vishr in https://github.com/labstack/echo/pull/2822
    • Fix typo in SetParamValues comment by @vishr in https://github.com/labstack/echo/pull/2828
    • Fix typo in ContextTimeout middleware comment by @vishr in https://github.com/labstack/echo/pull/2827
    • Improve BasicAuth middleware: use strings.Cut and RFC compliance by @vishr in https://github.com/labstack/echo/pull/2825
    • Fix duplicate plus operator in router backtracking logic by @yuya-morimoto in https://github.com/labstack/echo/pull/2832
    • Replace custom private IP range check with built-in net.IP.IsPrivate by @kumapower17 in https://github.com/labstack/echo/pull/2835
    • Ensure proxy connection is closed in proxyRaw function(#2837) by @kumapower17 in https://github.com/labstack/echo/pull/2838
    • Update deps by @aldas in https://github.com/labstack/echo/pull/2843
    • Update golang.org/x/* deps by @aldas in https://github.com/labstack/echo/pull/2850
    Open source →
  11. v4.13.5-0.20251122143322-612967a9fec122 Nov 2025pre-release

    Nothing published for this version

  12. v4.13.5-0.20251026172629-53b692c4d4de26 Oct 2025pre-release

    Nothing published for this version

  13. v4.13.5-0.20251015184624-e644ff8f7bb015 Oct 2025pre-release

    Nothing published for this version

  14. v4.13.5-0.20250926084813-55cb3b625d1226 Sept 2025pre-release

    Nothing published for this version

  15. v4.13.5-0.20250916050828-52d2bff1b9eb16 Sept 2025pre-release

    Nothing published for this version

  16. v4.13.5-0.20250829145306-5ac2f11f21b729 Aug 2025pre-release

    Nothing published for this version

  17. v4.13.5-0.20250825193258-9acf5341821c25 Aug 2025pre-release

    Nothing published for this version

  18. v4.13.5-0.20250812085752-8493c61ede5812 Aug 2025pre-release

    Nothing published for this version

  19. v4.13.422 May 2025
    Release notes2 sources agree

    Enhancements

    • chore: fix some typos in comment by @zhuhaicity in https://github.com/labstack/echo/pull/2735
    • CI: test with Go 1.24 by @aldas in https://github.com/labstack/echo/pull/2748
    • Add support for TLS WebSocket proxy by @t-ibayashi-safie in https://github.com/labstack/echo/pull/2762

    Security

    Open source →
  20. v4.13.4-0.20250404080142-de44c53a5b164 Apr 2025pre-release

    Nothing published for this version

  21. v4.13.4-0.20250212171734-c44f6283f02a12 Feb 2025pre-release

    Nothing published for this version

  22. v4.13.4-0.20250112072838-ce0b12ae531b12 Jan 2025pre-release

    Nothing published for this version

  23. v4.13.4-0.20250107200628-ee3e1297788e7 Jan 2025pre-release

    Nothing published for this version

  24. v4.13.319 Dec 2024
    Release notes2 sources agree

    Security

    • Update golang.org/x/net dependency GO-2024-3333 in https://github.com/labstack/echo/pull/2722
    Open source →
  25. v4.13.212 Dec 2024
    Release notes2 sources agree

    Security

    • Update dependencies (dependabot reports GO-2024-3321) in https://github.com/labstack/echo/pull/2721
    Open source →
  26. v4.13.111 Dec 2024
    Release notes2 sources agree

    Fixes

    • Fix BindBody ignoring Transfer-Encoding: chunked requests by @178inaba in https://github.com/labstack/echo/pull/2717
    Open source →
  27. v4.13.04 Dec 2024
    Release notes2 sources agree

    BREAKING CHANGE JWT Middleware Removed from Core use labstack/echo-jwt instead

    The JWT middleware has been removed from Echo core due to another security vulnerability, CVE-2024-51744. For more details, refer to issue #2699. A drop-in replacement is available in the labstack/echo-jwt repository.

    Important: Direct assignments like token := c.Get("user").(*jwt.Token) will now cause a panic due to an invalid cast. Update your code accordingly. Replace the current imports from "github.com/golang-jwt/jwt" in your handlers to the new middleware version using "github.com/golang-jwt/jwt/v5".

    Background:

    The version of golang-jwt/jwt (v3.2.2) previously used in Echo core has been in an unmaintained state for some time. This is not the first vulnerability affecting this library; earlier issues were addressed in PR #1946. JWT middleware was marked as deprecated in Echo core as of v4.10.0 on 2022-12-27. If you did not notice that, consider leveraging tools like Staticcheck to catch such deprecations earlier in you dev/CI flow. For bonus points - check out gosec.

    We sincerely apologize for any inconvenience caused by this change. While we strive to maintain backward compatibility within Echo core, recurring security issues with third-party dependencies have forced this decision.

    Enhancements

    • remove jwt middleware by @stevenwhitehead in https://github.com/labstack/echo/pull/2701
    • optimization: struct alignment by @behnambm in https://github.com/labstack/echo/pull/2636
    • bind: Maintain backwards compatibility for map[string]interface{} binding by @thesaltree in https://github.com/labstack/echo/pull/2656
    • Add Go 1.23 to CI by @aldas in https://github.com/labstack/echo/pull/2675
    • improve MultipartForm test by @martinyonatann in https://github.com/labstack/echo/pull/2682
    • bind : add support of multipart multi files by @martinyonatann in https://github.com/labstack/echo/pull/2684
    • Add TemplateRenderer struct to ease creating renderers for html/template and text/template packages. by @aldas in https://github.com/labstack/echo/pull/2690
    • Refactor TestBasicAuth to utilize table-driven test format by @ErikOlson in https://github.com/labstack/echo/pull/2688
    • Remove broken header by @aldas in https://github.com/labstack/echo/pull/2705
    • fix(bind body): content-length can be -1 by @phamvinhdat in https://github.com/labstack/echo/pull/2710
    • CORS middleware should compile allowOrigin regexp at creation by @aldas in https://github.com/labstack/echo/pull/2709
    • Shorten Github issue template and add test example by @aldas in https://github.com/labstack/echo/pull/2711
    Open source →
  28. v4.12.1-0.20241204201345-3b017855b4d34 Dec 2024pre-release

    Nothing published for this version

  29. v4.12.1-0.20241125202156-fe262777811425 Nov 2024pre-release

    Nothing published for this version

  30. v4.12.1-0.20241122205455-9e73691837f522 Nov 2024pre-release

    Nothing published for this version

  31. v4.12.1-0.20241118195643-5d98929328ad18 Nov 2024pre-release

    Nothing published for this version

  32. v4.12.1-0.20241026124447-5a0b4dd8063526 Oct 2024pre-release

    Nothing published for this version

  33. v4.12.1-0.20241020182151-822d11a465aa20 Oct 2024pre-release

    Nothing published for this version

  34. v4.12.1-0.20241006205323-ab87b63640f26 Oct 2024pre-release

    Nothing published for this version

  35. v4.12.1-0.20240816061652-d20a6257aa1216 Aug 2024pre-release

    Nothing published for this version

  36. v4.12.1-0.20240816061652-27c55f2189e016 Aug 2024pre-release

    Nothing published for this version

  37. v4.12.1-0.20240722043301-f13e2640f0ea22 Jul 2024pre-release

    Nothing published for this version

  38. v4.12.1-0.20240530195001-f7d9f5142e9a30 May 2024pre-release

    Nothing published for this version

  39. v4.12.015 Apr 2024
    Release notes2 sources agree

    Security

    • Update golang.org/x/net dep because of GO-2024-2687 by @aldas in https://github.com/labstack/echo/pull/2625

    Enhancements

    • binder: make binding to Map work better with string destinations by @aldas in https://github.com/labstack/echo/pull/2554
    • README.md: add Encore as sponsor by @marcuskohlberg in https://github.com/labstack/echo/pull/2579
    • Reorder paragraphs in README.md by @aldas in https://github.com/labstack/echo/pull/2581
    • CI: upgrade actions/checkout to v4 by @aldas in https://github.com/labstack/echo/pull/2584
    • Remove default charset from 'application/json' Content-Type header by @doortts in https://github.com/labstack/echo/pull/2568
    • CI: Use Go 1.22 by @aldas in https://github.com/labstack/echo/pull/2588
    • binder: allow binding to a nil map by @georgmu in https://github.com/labstack/echo/pull/2574
    • Add Skipper Unit Test In BasicBasicAuthConfig and Add More Detail Explanation regarding BasicAuthValidator by @RyoKusnadi in https://github.com/labstack/echo/pull/2461
    • fix some typos by @teslaedison in https://github.com/labstack/echo/pull/2603
    • fix: some typos by @pomadev in https://github.com/labstack/echo/pull/2596
    • Allow ResponseWriters to unwrap writers when flushing/hijacking by @aldas in https://github.com/labstack/echo/pull/2595
    • Add SPDX licence comments to files. by @aldas in https://github.com/labstack/echo/pull/2604
    • Upgrade deps by @aldas in https://github.com/labstack/echo/pull/2605
    • Change type definition blocks to single declarations. This helps copy… by @aldas in https://github.com/labstack/echo/pull/2606
    • Fix Real IP logic by @cl-bvl in https://github.com/labstack/echo/pull/2550
    • Default binder can use UnmarshalParams(params []string) error inter… by @aldas in https://github.com/labstack/echo/pull/2607
    • Default binder can bind pointer to slice as struct field. For example *[]string by @aldas in https://github.com/labstack/echo/pull/2608
    • Remove maxparam dependence from Context by @aldas in https://github.com/labstack/echo/pull/2611
    • When route is registered with empty path it is normalized to /. by @aldas in https://github.com/labstack/echo/pull/2616
    • proxy middleware should use httputil.ReverseProxy for SSE requests by @aldas in https://github.com/labstack/echo/pull/2624
    Open source →
  40. v4.11.5-0.20240415183101-88c379ff772715 Apr 2024pre-release

    Nothing published for this version

  41. v4.11.5-0.20240327102846-447c92d842e227 Mar 2024pre-release

    Nothing published for this version

  42. v4.11.5-0.20240321214216-d549290448fc21 Mar 2024pre-release

    Nothing published for this version

  43. v4.11.5-0.20240313200708-011acb4732fe13 Mar 2024pre-release

    Nothing published for this version

  44. v4.11.5-0.20240311204958-c57fcb3746c411 Mar 2024pre-release

    Nothing published for this version

  45. v4.11.5-0.20240310170454-a3b0ba24d35910 Mar 2024pre-release

    Nothing published for this version

  46. v4.11.5-0.20240309155307-3598f295f95f9 Mar 2024pre-release

    Nothing published for this version

  47. v4.11.5-0.20240309092813-5f7bedfb86e19 Mar 2024pre-release

    Nothing published for this version

  48. v4.11.5-0.20240306195253-3e04e3e2f25c6 Mar 2024pre-release

    Nothing published for this version

  49. v4.11.5-0.20240218134713-fa70db801e3d18 Feb 2024pre-release

    Nothing published for this version

  50. v4.11.5-0.20240213181618-ea529bbab66013 Feb 2024pre-release

    Nothing published for this version

  51. v4.11.5-0.20240207055421-29aab274b3817 Feb 2024pre-release

    Nothing published for this version

  52. v4.11.5-0.20240206054133-76994d17d59d6 Feb 2024pre-release

    Nothing published for this version

  53. v4.11.5-0.20240128151651-f12fdb09cd4d28 Jan 2024pre-release

    Nothing published for this version

  54. v4.11.5-0.20240124154540-b8354982419824 Jan 2024pre-release

    Nothing published for this version

  55. v4.11.5-0.20240123032605-d2621206908923 Jan 2024pre-release

    Nothing published for this version

  56. v4.11.5-0.20231220133251-60fc2fb1b76f20 Dec 2023pre-release

    Nothing published for this version

  57. v4.11.420 Dec 2023
    Release notes2 sources agree

    Security

    • Upgrade golang.org/x/crypto to v0.17.0 to fix vulnerability issue #2562

    Enhancements

    • Update deps and mark Go version to 1.18 as this is what golang.org/x/* use #2563
    • Request logger: add example for Slog https://pkg.go.dev/log/slog #2543
    Open source →
  58. v4.11.4-0.20231219160723-287a82c228ef19 Dec 2023pre-release

    Nothing published for this version

  59. v4.11.4-0.20231107130943-584cb85a6b747 Nov 2023pre-release

    Nothing published for this version

  60. v4.11.37 Nov 2023
    Release notes2 sources agree

    Security

    • 'c.Attachment' and 'c.Inline' should escape filename in 'Content-Disposition' header to avoid 'Reflect File Download' vulnerability. #2541

    Enhancements

    • Tests: refactor context tests to be separate functions #2540
    • Proxy middleware: reuse echo request context #2537
    • Mark unmarshallable yaml struct tags as ignored #2536
    Open source →