github.com/gofiber/fiber/v3
Go8 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/gofiber/fiber/v3page 1 of 1
- CVE-2026-25882HIGHCVSS 7.5EG 7.5✓ Fixed in 3.1.02026-02-24
Fiber is an Express inspired web framework written in Go. A denial of service vulnerability exists in Fiber v2 and v3 that allows remote attackers to crash the application by sending requests to routes with more than 30 parameters. The vul…
- CVE-2026-25891HIGHCVSS 7.5EG 7.5✓ Fixed in 3.1.02026-02-24
Fiber is an Express inspired web framework written in Go. A Path Traversal (CWE-22) vulnerability in Fiber allows a remote attacker to bypass the static middleware sanitizer and read arbitrary files on the server file system on Windows. Th…
- CVE-2026-25899HIGHCVSS 7.5EG 7.5✓ Fixed in 3.1.02026-02-24
Fiber is an Express inspired web framework written in Go. In versions on the v3 branch prior to 3.1.0, the use of the `fiber_flash` cookie can force an unbounded allocation on any server. A crafted 10-character cookie value triggers an att…
- CVE-2026-30246MEDIUMCVSS 6.5EG 6.5✓ Fixed in 3.2.02026-05-05
Fiber is a web framework for Go. In github.com/gofiber/fiber/v3 versions through 3.1.0, the default key generator in the cache middleware uses only the request path and does not include the query string. As a result, requests for the same …
- CVE-2026-42554MEDIUMCVSS 6.1EG 6.1✓ Fixed in 3.2.02026-05-11
Fiber is a web framework for Go. Prior to 2.52.12 and 3.1.0, Cross-Site Scripting vulnerability in Go Fiber allows a remote attacker to inject arbitrary HTML/JavaScript by supplying Accept: text/html on any request whose handler passes att…
- CVE-2026-44332MEDIUMCVSS 5.3EG 5.3✓ Fixed in 3.3.02026-07-02
Fiber is an Express inspired web framework written in Go. Prior to 3.3.0, the default Authorizer function in the BasicAuth middleware in middleware/basicauth/config.go uses short-circuit evaluation that skips password hash comparison for n…
- CVE-2026-45045MEDIUMCVSS 5.3EG 5.3✓ Fixed in 3.3.02026-07-02
Fiber is an Express inspired web framework written in Go. Prior to 3.3.0 and 2.52.14, the BalancerForward proxy helper in middleware/proxy/proxy.go uses Header.Add() instead of Header.Set() when injecting X-Real-IP, allowing an attacker-su…
- CVE-2026-53624MEDIUMCVSS 4.8EG 4.8✓ Fixed in 3.4.02026-07-06
Fiber is an Express inspired web framework written in Go. Prior to 3.4.0, the helmet middleware in middleware/helmet/helmet.go never sets the Strict-Transport-Security response header even when HSTSMaxAge is configured because it checks c.…
Check whether github.com/gofiber/fiber/v3 is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/gofiber/fiber/v3 CVEs against the assets you own.
Start Free Scan →