Skip to main content

Vendor archive

gofiber CVEs

Beta · best-effort

19 CVEs tagged to vendor gofiber6 Critical, 5 High, 8 Medium, 0 Low, 0 Unrated.

CVE-2026-53624

Published Jul 8, 2026

Fiber is an Express inspired web framework written in Go. Prior to 3.4.0, the helmet middleware in middleware/helmet/helmet.go never sets the Strict-Transport-Security response he…

CVSS 4.8 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-45045

Published Jul 8, 2026

Fiber is an Express inspired web framework written in Go. Prior to 3.3.0 and 2.52.14, the BalancerForward proxy helper in middleware/proxy/proxy.go uses Header.Add() instead of He…

CVSS 5.3 · Medium
evidence mentions
7
Buzz score
25.8
Vendor/product tagsBeta · best-effort

CVE-2026-44332

Published Jul 8, 2026

Fiber is an Express inspired web framework written in Go. Prior to 3.3.0, the default Authorizer function in the BasicAuth middleware in middleware/basicauth/config.go uses short-…

CVSS 5.3 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-42554

Published May 11, 2026

Fiber is a web framework for Go. Prior to 2.52.12 and 3.1.0, Cross-Site Scripting vulnerability in Go Fiber allows a remote attacker to inject arbitrary HTML/JavaScript by supplyi…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-30246

Published May 5, 2026

Fiber is a web framework for Go. In github.com/gofiber/fiber/v3 versions through 3.1.0, the default key generator in the cache middleware uses only the request path and does not i…

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-25899

Published Feb 24, 2026

Fiber is an Express inspired web framework written in Go. In versions on the v3 branch prior to 3.1.0, the use of the `fiber_flash` cookie can force an unbounded allocation on any…

CVSS 7.5 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-25891

Published Feb 24, 2026

Fiber is an Express inspired web framework written in Go. A Path Traversal (CWE-22) vulnerability in Fiber allows a remote attacker to bypass the static middleware sanitizer and r…

CVSS 7.7 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-25882

Published Feb 24, 2026

Fiber is an Express inspired web framework written in Go. A denial of service vulnerability exists in Fiber v2 and v3 that allows remote attackers to crash the application by send…

CVSS 5.5 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2025-66630

Published Feb 9, 2026

Fiber is an Express inspired web framework written in Go. Before 2.52.11, on Go versions prior to 1.24, the underlying crypto/rand implementation can return an error if secure ran…

CVSS 9.2 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-66565

Published Dec 9, 2025

Fiber Utils is a collection of common functions created for Fiber. In versions 2.0.0-rc.3 and below, when the system's cryptographic random number generator (crypto/rand) fails, b…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-54801

Published Aug 6, 2025

Fiber is an Express inspired web framework written in Go. In versions 2.52.8 and below, when using Fiber's Ctx.BodyParser to parse form data containing a large numeric key that re…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2025-48075

Published May 22, 2025

Fiber is an Express-inspired web framework written in Go. Starting in version 2.52.6 and prior to version 2.52.7, `fiber.Ctx.BodyParser` can map flat data to nested slices using `…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2024-38513

Published Jul 1, 2024

Fiber is an Express-inspired web framework written in Go A vulnerability present in versions prior to 2.52.5 is a session middleware issue in GoFiber versions 2 and above. This vu…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-25124

Published Feb 21, 2024

Fiber is a web framework written in go. Prior to version 2.52.1, the CORS middleware allows for insecure configurations that could potentially expose the application to multiple C…

CVSS 9.4 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-22199

Published Jan 11, 2024

This package provides universal methods to use multiple template engines with the Fiber web framework using the Views interface. This vulnerability specifically impacts web applic…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-45141

Published Oct 16, 2023

Fiber is an express inspired web framework written in Go. A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the application, which allows an attacker to obt…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2023-45128

Published Oct 16, 2023

Fiber is an express inspired web framework written in Go. A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the application, which allows an attacker to inj…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-41338

Published Sep 8, 2023

Fiber is an Express inspired web framework built in the go language. Versions of gofiber prior to 2.49.2 did not properly restrict access to localhost. This issue impacts users of…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-15111

Published Jul 20, 2020

In Fiber before version 1.12.6, the filename that is given in c.Attachment() (https://docs.gofiber.io/ctx#attachment) is not escaped, and therefore vulnerable for a CRLF injection…

CVSS 4.2 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-19 of 19 CVEsPage 1 of 1