Skip to content

Update module github.com/labstack/echo/v4 to v5 - #55

Open
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/github.com-labstack-echo-v4-5.x
Open

renovate[bot] wants to merge 1 commit into
masterfrom
renovate/github.com-labstack-echo-v4-5.x

Conversation

@renovate

@renovate renovate Bot commented Jan 20, 2026 •

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence
github.com/labstack/echo/v4 v4.2.0 → v5.4.0 age confidence

Release Notes

labstack/echo (github.com/labstack/echo/v4)

v5.4.0

Compare Source

Security

This release fixes several security issues. Upgrading is recommended. Some fixes change behavior; read "Behavior changes to check before upgrading" below.

  • Request scheme: Context.Scheme() now uses the X-Forwarded-Proto, X-Forwarded-Protocol, X-Forwarded-Ssl and X-Url-Scheme headers only when the request comes directly from a loopback, link-local or private network address or a unix socket. Before this, any client could send X-Forwarded-Proto: https over plain HTTP and skip HTTPSRedirect. When X-Forwarded-Proto is present, only it is used (its last value), and the scheme is returned in lowercase. Echo#SchemeExtractor (and Config.SchemeExtractor) selects the strategy: ExtractSchemeFromHeaders(...TrustOption) (default), ExtractSchemeDirect() or LegacySchemeExtractor(). The Secure middleware now sets HSTS based on Context.Scheme(). The Proxy middleware always sets X-Forwarded-Proto from Context.Scheme() and removes X-Forwarded-Ssl, X-Forwarded-Protocol and X-Url-Scheme before forwarding. GHSA-2ffq-g2xg-c22p
  • Proxy middleware: always sets X-Real-IP from Context.RealIP(), so a client can no longer pass a spoofed X-Real-IP to the upstream. GHSA-99jh-6h7p-pp36
  • JSONP: Context.JSONP and Context.JSONPBlob accept only a callback that is empty, a JavaScript identifier or a dot-separated path of identifiers (ASCII letters, digits, _ and $). Any other callback returns a 400 Bad Request error that wraps the new ErrInvalidJSONPCallback, and nothing is written. JSONP responses now carry X-Content-Type-Options: nosniff. JSONP lets any website read the response with the user's cookies, so do not use it for data that needs authentication. GHSA-h9g5-28mm-hx3g
  • MethodOverride: a POST can no longer be overridden to GET, HEAD, OPTIONS, TRACE or CONNECT. Before this, with the MethodFromForm or MethodFromQuery getter and MethodOverride registered with Use before the CSRF middleware, _method=GET skipped the CSRF check. Register MethodOverride with Echo#Pre. GHSA-r7w9-592q-9vg4
  • Redirects: the trailing slash middlewares and the static directory redirect percent-encode control characters in the redirect path. Before this, /%09/evil.example/ redirected browsers to evil.example. GHSA-v753-g4cw-jm48
  • Static files: with the default settings, the Static middleware resolves files from the same form of the path that the router matched, so /admin%2Fsecret.txt or /%61dmin/secret.txt can no longer reach a file under a guarded /admin/* route. GHSA-375p-5qhx-8wq4 The Static middleware and StaticDirectoryHandler (used by Echo.Static, Echo.StaticFS, Group.Static and Group.StaticFS) no longer serve paths with a ., .. or empty segment, such as /assets/../admin/secret.txt, also after path unescaping. GHSA-3pmx-cf9f-34xr

Behavior changes to check before upgrading

  • Proxies or load balancers with public IP addresses. If a proxy connects to your app from a public (or 100.64.0.0/10) address, its X-Forwarded-Proto is now ignored: HTTPSRedirect redirects in a loop and the Secure middleware stops sending HSTS. This affects, for example, Cloudflare, CloudFront and Azure Front Door connecting to a public origin, the GCP external HTTP(S) load balancer including GKE Ingress (35.191.0.0/16, 130.211.0.0/22), and networks that use 100.64.0.0/10 (such as Alibaba Cloud SLB or EKS custom networking). Trust the proxy's address ranges:
    _, gclb1, _ := net.ParseCIDR("35.191.0.0/16")
    _, gclb2, _ := net.ParseCIDR("130.211.0.0/22")
    e.SchemeExtractor = echo.ExtractSchemeFromHeaders(echo.TrustIPRange(gclb1), echo.TrustIPRange(gclb2))
    Proxies on the same host, in a private network (AWS ALB, in-cluster ingress controllers such as ingress-nginx or Traefik, most PaaS routers) or on a unix socket keep working without changes. echo.LegacySchemeExtractor() restores the old behavior but is not safe unless every request passes through a proxy that sets these headers. Serverless adapters or middleware that set RemoteAddr to the client's address also make X-Forwarded-Proto ignored (or, if they take it from a header, spoofable).
  • Trusted proxies must set X-Forwarded-Proto. A proxy on a trusted address that passes the client's X-Forwarded-Proto through (for example nginx without proxy_set_header X-Forwarded-Proto $scheme;) still lets the client choose the scheme. An invalid X-Forwarded-Proto value now results in http instead of falling back to the other scheme headers.
  • Your own tests. httptest.NewRequest sets RemoteAddr to 192.0.2.1:1234, which is not trusted, so tests that set X-Forwarded-Proto now see http. Set req.RemoteAddr = "10.0.0.1:1234" or use e.SchemeExtractor = echo.LegacySchemeExtractor() in such tests.
  • Proxy middleware headers. X-Real-IP sent to the upstream is now always Context.RealIP(). In a chain like nginx → Echo Proxy → upstream, configure Echo#IPExtractor (for example echo.ExtractIPFromRealIPHeader()) to pass the client address on. X-Forwarded-Ssl, X-Forwarded-Protocol and X-Url-Scheme are no longer forwarded; X-Forwarded-Proto carries the scheme.
  • MethodOverride. Overriding a POST to GET (for example with X-HTTP-Method-Override: GET to send a long query in a POST body) is no longer done; such requests keep the POST method.
  • Static files. Paths with a double slash or dot segment (for example /assets//app.js) now return 404; in HTML5 mode the index is still served. The Static middleware no longer finds file names that the client sends with non-default escaping (for example %2C, %40 or lowercase hex like %c3%a9) unless StaticConfig.EnablePathUnescaping is set; Echo.Static has behaved this way since v5.2.1. With StaticConfig.EnablePathUnescaping or Config.EnablePathUnescapingStaticFiles, encoded dots (%2e%2e) no longer traverse directories, but encoded slashes are still decoded, so do not combine these options with route-based access control.
  • JSONP. Context.JSONP returns an error for callbacks that are not JavaScript identifiers.

Documentation

  • IPExtractor docs: corrected the description of the default (the direct peer address has been used since v5.1.0).
  • Static middleware: when registered with Echo#Use it runs before route and group middleware, so route guards do not protect the files it serves.

v5.3.1

Compare Source

Fixes

  • fix(static): preserve matched handler 404s by @​JSap0914 in #​3043
  • fix(group): Implicitly registered group routes should be allowed overwritten in default routes by @​aldas in #​3049

Enhancements

v5.3.0

Compare Source

Logic changes
PR #​2996 revert back to v4 behavior for a group registering implicit 404 handlers.

If you do not want this behavior, can do not want implicit 404 handlers for groups, use:

e :=  echo.NewWithConfig(echo.Config{NoGroupAutoRegister404Routes: true})
g := e.Group("/api")

some other noteworthy echancements:

e.QUERY("/", func(c *Context) error {
  return c.String(http.StatusTeapot, "OK")
})
  • Router: automatically handle HEAD request by GET handlers in labtack#2949
e := echo.NewWithConfig(echo.Config{
  Router: echo.NewRouter(echo.RouterConfig{
    AutoHandleHEAD: true,
  }),
})

Enhancements

v5.2.1

Compare Source

Security

Make serving static file releated methods and middleware not unescape path by default - so how the way Router interprets paths and Static methods/middleware is consistent.

Given following situation:

// 0.
// given folder structure:
// private.txt
// public/
// public/index.html
// public/text.txt
// public/admin/private.txt

// 1. share `public/` folder contents from the server root. This folder actually contains subfolder `admin` which
// contents we want to forbid from downloading
e.Static("/", "public")

// 2. naively assume that everything under /admin folder is now forbidden
e.GET("/admin/*", func(c *Context) error {
    return ErrForbidden
})

Then requests to /admin%2fprivate.txt would not be matched to GET /admin/* route (routing does not look unescaped path) and static file serving will use unescaped path to serve the file.

Note: this way of "guarding" subfolders will never work for for paths like /assets/../admin%2fprivate.txt which will path.Clean("/assets/../admin%2fprivate.txt") to /admin/private.txt and are servable if static file serving is configured to unescape paths.

If you want to guard routes - use middlewares on Static* methods and before Static middleware.


  • revert PR #​3009 changes to just disabling path escaping by default in static methods/middleware by @​aldas in #​3016

Closes GHSA-vfp3-v2gw-7wfq more completely: the previous fix (#​3009) rejected explicitly encoded
separators at the handler level; this patch makes the no-unescape behavior the default so new configurations are safe without extra opt-out steps.

What changed: DisablePathUnescaping (on StaticConfig and StaticDirectoryHandlerConfig) is deprecated and replaced by EnablePathUnescaping (default false). Path unescaping is now opt-in.

What this protects: With EnablePathUnescaping: false (new default), encoded separators (%2F, %5C) are never decoded before routing or file lookup, so they cannot
bypass route-level authentication or other middleware guards.

What this does NOT protect: Serving a directory with Static, StaticFS, or StaticDirectoryHandler exposes its entire subtree. Sibling routes are not a reliable
ACL boundary — attach authorization middleware directly to the static mount, or serve sensitive sub-trees under separate guarded routes.

Breaking change / migration: If you serve files whose names contain URL-encoded characters (e.g., /hello%20world.txt → hello world.txt), you must now opt in:

// Static middleware
e.Use(middleware.StaticWithConfig(middleware.StaticConfig{
    EnablePathUnescaping: true, // only safe when NOT relying on route-based ACL guards
    ...
}))

// StaticDirectoryHandler
middleware.StaticDirectoryHandler(fs, &middleware.StaticDirectoryHandlerConfig{
    EnablePathUnescaping: true,
})

Full Changelog: labstack/echo@v5.2.0...v5.2.1

v5.2.0

Compare Source

Security

Fixes GHSA-vfp3-v2gw-7wfq: an encoded path separator (%2F or %5C) in a static file URL could bypass route-level middleware (e.g. authentication on a sibling route) and disclose static files. Both StaticDirectoryHandler/StaticFS and the Static middleware are affected. Thanks to @​a-tt-om and @​oran-gugu for reporting.

Enhancements

New Contributors

Full Changelog: labstack/echo@v5.1.1...v5.2.0

v5.1.1

Compare Source

Security

Thanks to @​shblue21 for reporting this issue.

Enhancements

v5.1.0

Compare Source

Security

This change does not break the API contract, but it does introduce breaking changes in logic/behavior.
If your application is using c.RealIP() beware and read https://echo.labstack.com/docs/ip-address

v4 behavior can be restored with:

e := echo.New()
e.IPExtractor = echo.LegacyIPExtractor()
  • Remove legacy IP extraction logic from context.RealIP method by @​aldas in #​2933

Enhancements

v5.0.4

Compare Source

Enhancements

v5.0.3

Compare Source

Security

  • Fix directory traversal vulnerability under Windows in Static middleware when default Echo filesystem is used. Reported by @​shblue21.

This applies to cases when:

  • Windows is used as OS
  • middleware.StaticConfig.Filesystem is nil (default)
  • echo.Filesystem is has not been set explicitly (default)

Exposure is restricted to the active process working directory and its subfolders.

v5.0.2

Compare Source

Security

  • Fix Static middleware with config.Browse=true lists all files/subfolders from config.Filesystem root and not starting from config.Root in #​2887

v5.0.1

Compare Source

v5.0.0

Compare Source

Echo v5 is maintenance release with major breaking changes

  • Context is now struct instead of interface and we can add method to it in the future in minor versions.
  • Adds new Router interface for possible new routing implementations.
  • Drops old logging interface and uses moderm log/slog instead.
  • Rearranges alot of methods/function signatures to make them more consistent.

Upgrade notes and v4 support:

  • Echo v4 is supported with security* updates and bug fixes until 2026-12-31
  • If you are using Echo in a production environment, it is recommended to wait until after 2026-03-31 before upgrading.
  • Until 2026-03-31, any critical issues requiring breaking v5 API changes will be addressed, even if this violates semantic versioning.

See API_CHANGES_V5.md for public API changes between v4 and v5, notes on upgrading.

Upgrading TLDR:

If you are using Linux you can migrate easier parts like that:

find . -type f -name "*.go" -exec sed -i 's/ echo.Context/ *echo.Context/g' {} +
find . -type f -name "*.go" -exec sed -i 's/echo\/v4/echo\/v5/g' {} +

macOS

find . -type f -name "*.go" -exec sed -i '' 's/ echo.Context/ *echo.Context/g' {} +
find . -type f -name "*.go" -exec sed -i '' 's/echo\/v4/echo\/v5/g' {} +

or in your favorite IDE

Replace all:

  1. echo.Context -> *echo.Context
  2. echo/v4 -> echo/v5

This should solve most of the issues. Probably the hardest part is updating all the tests.

v4.16.0

Compare Source

Security

This release fixes several security issues. Upgrading is recommended. Some fixes change behavior; read "Behavior changes to check before upgrading" below.

  • Request scheme: Context.Scheme() now uses the X-Forwarded-Proto, X-Forwarded-Protocol, X-Forwarded-Ssl and X-Url-Scheme headers only when the request comes directly from a loopback, link-local or private network address or a unix socket. Before this, any client could send X-Forwarded-Proto: https over plain HTTP and skip HTTPSRedirect. When X-Forwarded-Proto is present, only it is used (its last value), and the scheme is returned in lowercase. the new Echo#SchemeExtractor field selects the strategy: ExtractSchemeFromHeaders(...TrustOption) (default), ExtractSchemeDirect() or LegacySchemeExtractor(). The Secure middleware now sets HSTS based on Context.Scheme(). The Proxy middleware always sets X-Forwarded-Proto from Context.Scheme() and removes X-Forwarded-Ssl, X-Forwarded-Protocol and X-Url-Scheme before forwarding. GHSA-2ffq-g2xg-c22p
  • JSONP: Context.JSONP and Context.JSONPBlob accept only a callback that is empty, a JavaScript identifier or a dot-separated path of identifiers (ASCII letters, digits, _ and $). Any other callback returns a 400 Bad Request error that wraps the new ErrInvalidJSONPCallback, and nothing is written. JSONP responses now carry X-Content-Type-Options: nosniff. JSONP lets any website read the response with the user's cookies, so do not use it for data that needs authentication. GHSA-h9g5-28mm-hx3g
  • MethodOverride: a POST can no longer be overridden to GET, HEAD, OPTIONS, TRACE or CONNECT. Before this, with the MethodFromForm or MethodFromQuery getter and MethodOverride registered with Use before the CSRF middleware, _method=GET skipped the CSRF check. Register MethodOverride with Echo#Pre. GHSA-r7w9-592q-9vg4
  • Redirects: the trailing slash middlewares and the static directory redirect percent-encode control characters in the redirect path. Before this, /%09/evil.example/ redirected browsers to evil.example. GHSA-v753-g4cw-jm48
  • Static files: with the default settings, the Static middleware resolves files from the same form of the path that the router matched, so /admin%2Fsecret.txt or /%61dmin/secret.txt can no longer reach a file under a guarded /admin/* route. GHSA-375p-5qhx-8wq4 The Static middleware and StaticDirectoryHandler (used by Echo.Static, Echo.StaticFS, Group.Static and Group.StaticFS) no longer serve paths with a ., .. or empty segment, such as /assets/../admin/secret.txt, also after path unescaping. GHSA-3pmx-cf9f-34xr
  • Dependencies: update golang.org/x/text to v0.40.0 (GO-2026-5970).

Client IP address (no code change in v4)

Without Echo#IPExtractor, Context.RealIP() in v4 trusts the X-Forwarded-For and X-Real-IP headers from any client, so the rate limiter can be bypassed and the Proxy middleware forwards a spoofed X-Real-IP (GHSA-246p-cpwv-v3jq, GHSA-99jh-6h7p-pp36). Changing this default in v4 would put all clients behind a proxy into one rate-limit bucket, so v4 keeps it. Set an extractor that matches your deployment:

e.IPExtractor = echo.ExtractIPDirect()        // no proxy in front of the app
e.IPExtractor = echo.ExtractIPFromXFFHeader() // behind proxies in private networks that set X-Forwarded-For
// behind a proxy with public addresses (e.g. a CDN), also trust its ranges:
// e.IPExtractor = echo.ExtractIPFromXFFHeader(echo.TrustIPRange(cdnRange))

v5 uses the direct peer address by default since v5.1.0.

Behavior changes to check before upgrading

  • Proxies or load balancers with public IP addresses. If a proxy connects to your app from a public (or 100.64.0.0/10) address, its X-Forwarded-Proto is now ignored: HTTPSRedirect redirects in a loop and the Secure middleware stops sending HSTS. This affects, for example, Cloudflare, CloudFront and Azure Front Door connecting to a public origin, the GCP external HTTP(S) load balancer including GKE Ingress (35.191.0.0/16, 130.211.0.0/22), and networks that use 100.64.0.0/10 (such as Alibaba Cloud SLB or EKS custom networking). Trust the proxy's address ranges:
    _, gclb1, _ := net.ParseCIDR("35.191.0.0/16")
    _, gclb2, _ := net.ParseCIDR("130.211.0.0/22")
    e.SchemeExtractor = echo.ExtractSchemeFromHeaders(echo.TrustIPRange(gclb1), echo.TrustIPRange(gclb2))
    Proxies on the same host, in a private network (AWS ALB, in-cluster ingress controllers such as ingress-nginx or Traefik, most PaaS routers) or on a unix socket keep working without changes. echo.LegacySchemeExtractor() restores the old behavior but is not safe unless every request passes through a proxy that sets these headers. Serverless adapters or middleware that set RemoteAddr to the client's address also make X-Forwarded-Proto ignored (or, if they take it from a header, spoofable).
  • Trusted proxies must set X-Forwarded-Proto. A proxy on a trusted address that passes the client's X-Forwarded-Proto through (for example nginx without proxy_set_header X-Forwarded-Proto $scheme;) still lets the client choose the scheme. An invalid X-Forwarded-Proto value now results in http instead of falling back to the other scheme headers.
  • Your own tests. httptest.NewRequest sets RemoteAddr to 192.0.2.1:1234, which is not trusted, so tests that set X-Forwarded-Proto now see http. Set req.RemoteAddr = "10.0.0.1:1234" or use e.SchemeExtractor = echo.LegacySchemeExtractor() in such tests.
  • Proxy middleware headers. X-Forwarded-Ssl, X-Forwarded-Protocol and X-Url-Scheme are no longer forwarded to the upstream; X-Forwarded-Proto carries the scheme.
  • MethodOverride. Overriding a POST to GET (for example with X-HTTP-Method-Override: GET to send a long query in a POST body) is no longer done; such requests keep the POST method.
  • Static files. Paths with a double slash or dot segment (for example /assets//app.js) now return 404; in HTML5 mode the index is still served. The Static middleware no longer finds file names that the client sends with non-default escaping (for example %2C, %40 or lowercase hex like %c3%a9) unless StaticConfig.EnablePathUnescaping is set; Echo.Static has behaved this way since v4.15.4. With StaticConfig.EnablePathUnescaping or Echo#EnablePathUnescapingStaticFiles, encoded dots (%2e%2e) no longer traverse directories, but encoded slashes are still decoded, so do not combine these options with route-based access control.
  • JSONP. Context.JSONP returns an error for callbacks that are not JavaScript identifiers.

Documentation

  • Static middleware: when registered with Echo#Use it runs before route and group middleware, so route guards do not protect the files it serves.

v4.15.4

Compare Source

Security

Fixes GHSA-vfp3-v2gw-7wfq: an encoded path separator (%2F or %5C) in a static file URL could bypass route-level middleware (e.g. authentication on a sibling route) and disclose static files. Both StaticDirectoryHandler (used by Static/StaticFS) and the Static middleware are affected. Backport of the v5 fix (#​3016, released in v5.2.1). Thanks to @​a-tt-om and @​oran-gugu for reporting.


Make serving static file releated methods and middleware not unescape path by default - so how the way Router interprets paths and Static methods/middleware is consistent.

Given following situation:

// 0.
// given folder structure:
// private.txt
// public/
// public/index.html
// public/text.txt
// public/admin/private.txt

// 1. share `public/` folder contents from the server root. This folder actually contains subfolder `admin` which
// contents we want to forbid from downloading
e.Static("/", "public")

// 2. naively assume that everything under /admin folder is now forbidden
e.GET("/admin/*", func(c *Context) error {
    return ErrForbidden
})

Then requests to /admin%2fprivate.txt would not be matched to GET /admin/* route (routing does not look unescaped path) and static file serving will use unescaped path to serve the file.

Note: this way of "guarding" subfolders will never work for for paths like /assets/../admin%2fprivate.txt which will path.Clean("/assets/../admin%2fprivate.txt") to /admin/private.txt and are servable if static file serving is configured to unescape paths.

If you want to guard routes - use middlewares on Static* methods and before Static middleware.

Breaking change / migration: If you serve files whose names contain URL-encoded characters (e.g., /hello%20world.txt → hello world.txt), you must now opt in:

	e := echo.New()
	e.EnablePathUnescapingStaticFiles = true  // <-- enable old behavior
	e.Static("/", "public")

for static middleware

	e.Use(middleware.StaticWithConfig(middleware.StaticConfig{
		EnablePathUnescaping: true, // <-- enable old behavior
	}))

Full Changelog: labstack/echo@v4.15.3...v4.15.4

v4.15.3: - Static encoded-separator route bypass fix (GHSA-vfp3-v2gw-7wfq)

Compare Source

Security

  • fix(static): reject encoded path separators that bypass route-level middleware by @​vishr in #​3011

Fixes GHSA-vfp3-v2gw-7wfq: an encoded path separator (%2F or %5C) in a static file URL could bypass route-level middleware (e.g. authentication on a sibling route) and disclose static files. Both StaticDirectoryHandler (used by Static/StaticFS) and the Static middleware are affected. Backport of the v5 fix (#​3009, released in v5.2.0). Thanks to @​a-tt-om and @​oran-gugu for reporting.

Full Changelog: labstack/echo@v4.15.2...v4.15.3

v4.15.2: - Context.Scheme() header validation

Compare Source

Security

Thanks to @​shblue21 for reporting this issue.

Full Changelog: labstack/echo@v4.15.1...v4.15.2

v4.15.1

Compare Source

What's Changed

  • CSRF: support older token-based CSRF protection handler that want to render token into template by @​aldas in #​2905

Full Changelog: labstack/echo@v4.15.0...v4.15.1

v4.15.0

Compare Source

Security

NB: If your application relies on cross-origin or same-site (same subdomain) requests do not blindly push this version to production

The CSRF middleware now supports the Sec-Fetch-Site header as a modern, defense-in-depth approach to CSRF
protection
, implementing the OWASP-recommended Fetch Metadata API alongside the traditional token-based mechanism.

How it works:

Modern browsers automatically send the Sec-Fetch-Site header with all requests, indicating the relationship
between the request origin and the target. The middleware uses this to make security decisions:

  • same-origin or none: Requests are allowed (exact origin match or direct user navigation)
  • same-site: Falls back to token validation (e.g., subdomain to main domain)
  • cross-site: Blocked by default with 403 error for unsafe methods (POST, PUT, DELETE, PATCH)

For browsers that don't send this header (older browsers), the middleware seamlessly falls back to
traditional token-based CSRF protection.

New Configuration Options:

  • TrustedOrigins []string: Allowlist specific origins for cross-site requests (useful for OAuth callbacks, webhooks)
  • AllowSecFetchSiteFunc func(echo.Context) (bool, error): Custom logic for same-site/cross-site request validation

Example:

e.Use(middleware.CSRFWithConfig(middleware.CSRFConfig{
    // Allow OAuth callbacks from trusted provider
    TrustedOrigins: []string{"https://oauth-provider.com"},

    // Custom validation for same-site requests
    AllowSecFetchSiteFunc: func(c echo.Context) (bool, error) {
        // Your custom authorization logic here
        return validateCustomAuth(c), nil
        // return true, err  // blocks request with error
        // return true, nil  // allows CSRF request through
        // return false, nil // falls back to legacy token logic
    },
}))

PR: #​2858

Type-Safe Generic Parameter Binding

  • Added generic functions for type-safe parameter extraction and context access by @​aldas in #​2856

    Echo now provides generic functions for extracting path, query, and form parameters with automatic type conversion,
    eliminating manual string parsing and type assertions.

    New Functions:

    • Path parameters: PathParam[T], PathParamOr[T]
    • Query parameters: QueryParam[T], QueryParamOr[T], QueryParams[T], QueryParamsOr[T]
    • Form values: FormParam[T], FormParamOr[T], FormParams[T], FormParamsOr[T]
    • Context store: ContextGet[T], ContextGetOr[T]

    Supported Types:
    Primitives (bool, string, int/uint variants, float32/float64), time.Duration, time.Time
    (with custom layouts and Unix timestamp support), and custom types implementing BindUnmarshaler,
    TextUnmarshaler, or JSONUnmarshaler.

    Example:

    // Before: Manual parsing
    idStr := c.Param("id")
    id, err := strconv.Atoi(idStr)
    
    // After: Type-safe with automatic parsing
    id, err := echo.PathParam[int](c, "id")
    
    // With default values
    page, err := echo.QueryParamOr[int](c, "page", 1)
    limit, err := echo.QueryParamOr[int](c, "limit", 20)
    
    // Type-safe context access (no more panics from type assertions)
    user, err := echo.ContextGet[*User](c, "user")

PR: #​2856

DEPRECATION NOTICE Timeout Middleware Deprecated - Use ContextTimeout Instead

The middleware.Timeout middleware has been deprecated due to fundamental architectural issues that cause
data races. Use middleware.ContextTimeout or middleware.ContextTimeoutWithConfig instead.

Why is this being deprecated?

The Timeout middleware manipulates response writers across goroutine boundaries, which causes data races that
cannot be reliably fixed without a complete architectural redesign. The middleware:

  • Swaps the response writer using http.TimeoutHandler
  • Must be the first middleware in the chain (fragile constraint)
  • Can cause races with other middleware (Logger, metrics, custom middleware)
  • Has been the source of multiple race condition fixes over the years

What should you use instead?

The ContextTimeout middleware (available since v4.12.0) provides timeout functionality using Go's standard
context mechanism. It is:

  • Race-free by design
  • Can be placed anywhere in the middleware chain
  • Simpler and more maintainable
  • Compatible with all other middleware

Migration Guide:

// Before (deprecated):
e.Use(middleware.Timeout())

// After (recommended):
e.Use(middleware.ContextTimeout(30 * time.Second))

Important Behavioral Differences:

  1. Handler cooperation required: With ContextTimeout, your handlers must check context.Done() for cooperative
    cancellation. The old Timeout middleware would send a 503 response regardless of handler cooperation, but had
    data race issues.

  2. Error handling: ContextTimeout returns errors through the standard error handling flow. Handlers that receive
    context.DeadlineExceeded should handle it appropriately:

e.GET("/long-task", func(c echo.Context) error {
    ctx := c.Request().Context()

    // Example: database query with context
    result, err := db.QueryContext(ctx, "SELECT * FROM large_table")
    if err != nil {
        if errors.Is(err, context.DeadlineExceeded) {
            // Handle timeout
            return echo.NewHTTPError(http.StatusServiceUnavailable, "Request timeout")
        }
        return err
    }

    return c.JSON(http.StatusOK, result)
})
  1. Background tasks: For long-running background tasks, use goroutines with context:
e.GET("/async-task", func(c echo.Context) error {
    ctx := c.Request().Context()

    resultCh := make(chan Result, 1)
    errCh := make(chan error, 1)

    go func() {
        result, err := performLongTask(ctx)
        if err != nil {
            errCh <- err
            return
        }
        resultCh <- result
    }()

    select {
    case result := <-resultCh:
        return c.JSON(http.StatusOK, result)
    case err := <-errCh:
        return err
    case <-ctx.Done():
        return echo.NewHTTPError(http.StatusServiceUnavailable, "Request timeout")
    }
})

Enhancements

v4.14.0

Compare Source

middleware.Logger has been deprecated. For request logging, use middleware.RequestLogger or
middleware.RequestLoggerWithConfig.

middleware.RequestLogger replaces middleware.Logger, offering comparable configuration while relying on the
Go standard library’s new slog logger.

The previous default output format was JSON. The new default follows the standard slog logger settings.
To continue emitting request logs in JSON, configure slog accordingly:

slog.SetDefault(slog.New(slog.NewJSONHandler(os.Stdout, nil)))
e.Use(middleware.RequestLogger())

Security

Enhancements

v4.13.4

Compare Source

Enhancements

Security

v4.13.3

Compare Source

Security

v4.13.2

Compare Source

Security

v4.13.1

Compare Source

Fixes

v4.13.0

Compare Source

BREAKING CHANGE JWT Middleware Removed from Core use labstack/echo-jwt instead

The JWT middleware has been removed from Echo core due to another security vulnerability, CVE-2024-51744. For more details, refer to issue #​2699. A drop-in replacement is available in the labstack/echo-jwt repository.

Important: Direct assignments like token := c.Get("user").(*jwt.Token) will now cause a panic due to an invalid cast. Update your code accordingly. Replace the current imports from "github.com/golang-jwt/jwt" in your handlers to the new middleware version using "github.com/golang-jwt/jwt/v5".

Background:

The version of golang-jwt/jwt (v3.2.2) previously used in Echo core has been in an unmaintained state for some time. This is not the first vulnerability affecting this library; earlier issues were addressed in PR #​1946.
JWT middleware was marked as deprecated in Echo core as of [v4.10.0](https://redirect.github.com/labsta

❗ Important

✂ PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate

renovate Bot commented Jan 20, 2026 •

Copy link
Copy Markdown
Contributor Author

⚠️ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: go.sum
go: errors parsing go.mod:
go.mod:20:2: replace github.com/labstack/echo/v4: version "v5.4.0" invalid: should be v4, not v5

@renovate
renovate Bot force-pushed the renovate/github.com-labstack-echo-v4-5.x branch 2 times, most recently from b980bda to e3eb2d2 Compare February 2, 2026 21:53
@renovate
renovate Bot force-pushed the renovate/github.com-labstack-echo-v4-5.x branch from e3eb2d2 to 88800b8 Compare February 6, 2026 16:47
@renovate
renovate Bot force-pushed the renovate/github.com-labstack-echo-v4-5.x branch from 88800b8 to 91ec4ec Compare February 15, 2026 16:43
@renovate renovate Bot changed the title Update module github.com/labstack/echo/v4 to v5 Update module github.com/labstack/echo/v4 to v5 - autoclosed Mar 30, 2026
@renovate renovate Bot closed this Mar 30, 2026
@renovate
renovate Bot deleted the renovate/github.com-labstack-echo-v4-5.x branch March 30, 2026 13:50
@renovate renovate Bot changed the title Update module github.com/labstack/echo/v4 to v5 - autoclosed Update module github.com/labstack/echo/v4 to v5 Mar 30, 2026
@renovate renovate Bot reopened this Mar 30, 2026
@renovate
renovate Bot force-pushed the renovate/github.com-labstack-echo-v4-5.x branch 3 times, most recently from 57e4b1c to 84e7e0f Compare April 1, 2026 01:24
@renovate renovate Bot changed the title Update module github.com/labstack/echo/v4 to v5 Update module github.com/labstack/echo/v4 to v5 - autoclosed Apr 29, 2026
@renovate renovate Bot closed this Apr 29, 2026
@renovate renovate Bot changed the title Update module github.com/labstack/echo/v4 to v5 - autoclosed Update module github.com/labstack/echo/v4 to v5 Apr 29, 2026
@renovate renovate Bot reopened this Apr 29, 2026
@renovate
renovate Bot force-pushed the renovate/github.com-labstack-echo-v4-5.x branch 3 times, most recently from 19486bc to 08eefc4 Compare May 1, 2026 20:50
@renovate
renovate Bot force-pushed the renovate/github.com-labstack-echo-v4-5.x branch 2 times, most recently from 9776a1d to 6c84fdc Compare June 16, 2026 00:37
@renovate renovate Bot changed the title Update module github.com/labstack/echo/v4 to v5 Update module github.com/labstack/echo/v4 to v5 - autoclosed Jun 21, 2026
@renovate renovate Bot closed this Jun 21, 2026
@renovate renovate Bot changed the title Update module github.com/labstack/echo/v4 to v5 - autoclosed Update module github.com/labstack/echo/v4 to v5 Jun 21, 2026
@renovate renovate Bot reopened this Jun 21, 2026
@renovate
renovate Bot force-pushed the renovate/github.com-labstack-echo-v4-5.x branch 2 times, most recently from 6c84fdc to 5b7d5e8 Compare June 21, 2026 21:36
@renovate
renovate Bot force-pushed the renovate/github.com-labstack-echo-v4-5.x branch from 5b7d5e8 to a7db89c Compare July 12, 2026 22:43
@renovate
renovate Bot force-pushed the renovate/github.com-labstack-echo-v4-5.x branch from a7db89c to 1ffb5c9 Compare July 21, 2026 18:44
@renovate renovate Bot changed the title Update module github.com/labstack/echo/v4 to v5 Update module github.com/labstack/echo/v4 to v5 - autoclosed Aug 10, 2026
@renovate renovate Bot closed this Aug 10, 2026
@renovate renovate Bot changed the title Update module github.com/labstack/echo/v4 to v5 - autoclosed Update module github.com/labstack/echo/v4 to v5 Aug 10, 2026
@renovate renovate Bot reopened this Aug 10, 2026
@renovate
renovate Bot force-pushed the renovate/github.com-labstack-echo-v4-5.x branch 2 times, most recently from b65fa83 to ac8cb5a Compare August 10, 2026 14:11
@renovate renovate Bot changed the title Update module github.com/labstack/echo/v4 to v5 Update module github.com/labstack/echo/v4 to v5 - autoclosed Aug 18, 2026
@renovate renovate Bot closed this Aug 18, 2026
@renovate renovate Bot changed the title Update module github.com/labstack/echo/v4 to v5 - autoclosed Update module github.com/labstack/echo/v4 to v5 Aug 18, 2026
@renovate renovate Bot reopened this Aug 18, 2026
@renovate
renovate Bot force-pushed the renovate/github.com-labstack-echo-v4-5.x branch 2 times, most recently from ac8cb5a to 59eb2a8 Compare August 18, 2026 04:58
@renovate renovate Bot changed the title Update module github.com/labstack/echo/v4 to v5 Update module github.com/labstack/echo/v4 to v5 - autoclosed Aug 19, 2026
@renovate renovate Bot closed this Aug 19, 2026
@renovate renovate Bot changed the title Update module github.com/labstack/echo/v4 to v5 - autoclosed Update module github.com/labstack/echo/v4 to v5 Aug 19, 2026
@renovate renovate Bot reopened this Aug 19, 2026
@renovate
renovate Bot force-pushed the renovate/github.com-labstack-echo-v4-5.x branch 2 times, most recently from 59eb2a8 to 291105a Compare August 19, 2026 17:35
@renovate renovate Bot changed the title Update module github.com/labstack/echo/v4 to v5 Update module github.com/labstack/echo/v4 to v5 - autoclosed Aug 24, 2026
@renovate renovate Bot closed this Aug 24, 2026
@renovate renovate Bot changed the title Update module github.com/labstack/echo/v4 to v5 - autoclosed Update module github.com/labstack/echo/v4 to v5 Aug 24, 2026
@renovate renovate Bot reopened this Aug 24, 2026
@renovate
renovate Bot force-pushed the renovate/github.com-labstack-echo-v4-5.x branch 2 times, most recently from 291105a to bed6fc4 Compare August 24, 2026 22:43
@renovate renovate Bot changed the title Update module github.com/labstack/echo/v4 to v5 Update module github.com/labstack/echo/v4 to v5 - autoclosed Aug 27, 2026
@renovate renovate Bot closed this Aug 27, 2026
@renovate renovate Bot changed the title Update module github.com/labstack/echo/v4 to v5 - autoclosed Update module github.com/labstack/echo/v4 to v5 Aug 28, 2026
@renovate renovate Bot reopened this Aug 28, 2026
@renovate
renovate Bot force-pushed the renovate/github.com-labstack-echo-v4-5.x branch from 5686990 to bed6fc4 Compare August 28, 2026 01:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants