CVE-2026-25882
- EPSS 0.05%
- Veröffentlicht 24.02.2026 21:16:29
- Zuletzt bearbeitet 27.02.2026 03:18:05
Fiber is an Express inspired web framework written in Go. A denial of service vulnerability exists in Fiber v2 and v3 that allows remote attackers to crash the application by sending requests to routes with more than 30 parameters. The vulnerability ...
CVE-2026-25899
- EPSS 0.12%
- Veröffentlicht 24.02.2026 21:11:17
- Zuletzt bearbeitet 25.02.2026 20:31:50
Fiber is an Express inspired web framework written in Go. In versions on the v3 branch prior to 3.1.0, the use of the `fiber_flash` cookie can force an unbounded allocation on any server. A crafted 10-character cookie value triggers an attempt to all...
CVE-2026-25891
- EPSS 0.02%
- Veröffentlicht 24.02.2026 21:08:48
- Zuletzt bearbeitet 27.02.2026 03:18:58
Fiber is an Express inspired web framework written in Go. A Path Traversal (CWE-22) vulnerability in Fiber allows a remote attacker to bypass the static middleware sanitizer and read arbitrary files on the server file system on Windows. This affects ...
CVE-2025-66630
- EPSS 0.02%
- Veröffentlicht 09.02.2026 18:16:04
- Zuletzt bearbeitet 28.02.2026 00:26:20
Fiber is an Express inspired web framework written in Go. Before 2.52.11, on Go versions prior to 1.24, the underlying crypto/rand implementation can return an error if secure randomness cannot be obtained. Because no error is returned by the Fiber v...
CVE-2025-54801
- EPSS 0.07%
- Veröffentlicht 05.08.2025 23:33:28
- Zuletzt bearbeitet 23.09.2025 23:27:27
Fiber is an Express inspired web framework written in Go. In versions 2.52.8 and below, when using Fiber's Ctx.BodyParser to parse form data containing a large numeric key that represents a slice index (e.g., test.18446744073704), the application cra...
CVE-2025-48075
- EPSS 0.17%
- Veröffentlicht 22.05.2025 17:25:18
- Zuletzt bearbeitet 30.05.2025 01:18:13
Fiber is an Express-inspired web framework written in Go. Starting in version 2.52.6 and prior to version 2.52.7, `fiber.Ctx.BodyParser` can map flat data to nested slices using `key[idx]value` syntax, but when idx is negative, it causes a panic inst...
CVE-2024-38513
- EPSS 0.33%
- Veröffentlicht 01.07.2024 19:15:05
- Zuletzt bearbeitet 02.10.2025 13:55:12
Fiber is an Express-inspired web framework written in Go A vulnerability present in versions prior to 2.52.5 is a session middleware issue in GoFiber versions 2 and above. This vulnerability allows users to supply their own session_id value, resultin...
CVE-2024-25124
- EPSS 0.37%
- Veröffentlicht 21.02.2024 21:15:09
- Zuletzt bearbeitet 05.02.2025 22:03:51
Fiber is a web framework written in go. Prior to version 2.52.1, the CORS middleware allows for insecure configurations that could potentially expose the application to multiple CORS-related vulnerabilities. Specifically, it allows setting the Access...
CVE-2023-45128
- EPSS 0.16%
- Veröffentlicht 16.10.2023 21:15:11
- Zuletzt bearbeitet 21.11.2024 08:26:23
Fiber is an express inspired web framework written in Go. A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the application, which allows an attacker to inject arbitrary values and forge malicious requests on behalf of a user. ...
CVE-2023-45141
- EPSS 0.12%
- Veröffentlicht 16.10.2023 21:15:11
- Zuletzt bearbeitet 21.11.2024 08:26:25
Fiber is an express inspired web framework written in Go. A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the application, which allows an attacker to obtain tokens and forge malicious requests on behalf of a user. This can l...