📦 Fiber

by Gofiber

🔍 What is Fiber?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-66630

CRITICAL CVSS 9.4 Feb 9, 2026

Fiber web framework versions before 2.52.11 on Go versions prior to 1.24 may generate predictable UUIDs when crypto/rand fails to obtain secure randomness. This affects security-critical pathways usin...

CVE-2024-38513

CRITICAL CVSS 10.0 Jul 1, 2024

This vulnerability in GoFiber's session middleware allows attackers to supply their own session_id, enabling session fixation attacks and unauthorized access. All users of GoFiber versions 2 through 2...

CVE-2023-45128

CRITICAL CVSS 10.0 Oct 16, 2023

This CVE describes a critical CSRF vulnerability in the Fiber web framework for Go that allows attackers to forge malicious requests on behalf of users. Attackers can inject arbitrary values without a...

CVE-2026-25891

HIGH CVSS 7.5 Feb 24, 2026

A path traversal vulnerability in Fiber's static middleware on Windows allows remote attackers to bypass sanitization and read arbitrary files from the server filesystem. This affects Fiber v3 through...

CVE-2026-25899

HIGH CVSS 7.5 Feb 24, 2026

CVE-2026-25899 is a memory exhaustion vulnerability in GoFiber v3 web framework where a specially crafted 10-character cookie value triggers unvalidated msgpack deserialization, attempting to allocate...

CVE-2025-48075

HIGH CVSS 7.5 May 22, 2025

A denial-of-service vulnerability in Go's Fiber web framework allows attackers to crash applications by sending specially crafted requests with negative array indices. This affects all applications us...