Gofiber
Gofiber Fiber: vulnerabilidades y CVE
Gofiber Fiber tiene 17 vulnerabilidades publicadas, 9 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE17
Últimos 12 meses9
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-53624 | Media (4.8) | 0.21% | — | 8 jul 2026 | Fiber is an Express inspired web framework written in Go. Prior to 3.4.0, the helmet middleware in middleware/helmet/helmet.go never sets the Strict-Transport-Security response header even when HSTSMaxAge is configured… |
| CVE-2026-45045 | Media (5.3) | 0.46% | — | 8 jul 2026 | Fiber is an Express inspired web framework written in Go. Prior to 3.3.0 and 2.52.14, the BalancerForward proxy helper in middleware/proxy/proxy.go uses Header.Add() instead of Header.Set() when injecting X-Real-IP,… |
| CVE-2026-44332 | Media (5.3) | 0.52% | — | 8 jul 2026 | Fiber is an Express inspired web framework written in Go. Prior to 3.3.0, the default Authorizer function in the BasicAuth middleware in middleware/basicauth/config.go uses short-circuit evaluation that skips password… |
| CVE-2026-42554 | Media (5.3) | 0.31% | — | 11 may 2026 | Fiber is a web framework for Go. Prior to 2.52.12 and 3.1.0, Cross-Site Scripting vulnerability in Go Fiber allows a remote attacker to inject arbitrary HTML/JavaScript by supplying Accept: text/html on any request… |
| CVE-2026-30246 | Media (6.5) | 0.37% | — | 5 may 2026 | Fiber is a web framework for Go. In github.com/gofiber/fiber/v3 versions through 3.1.0, the default key generator in the cache middleware uses only the request path and does not include the query string. As a result,… |
| CVE-2026-25899 | Alta (7.5) | 0.63% | — | 24 feb 2026 | Fiber is an Express inspired web framework written in Go. In versions on the v3 branch prior to 3.1.0, the use of the `fiber_flash` cookie can force an unbounded allocation on any server. A crafted 10-character cookie… |
| CVE-2026-25891 | Alta (7.7) | 0.69% | — | 24 feb 2026 | Fiber is an Express inspired web framework written in Go. A Path Traversal (CWE-22) vulnerability in Fiber allows a remote attacker to bypass the static middleware sanitizer and read arbitrary files on the server file… |
| CVE-2026-25882 | Media (5.5) | 0.81% | — | 24 feb 2026 | Fiber is an Express inspired web framework written in Go. A denial of service vulnerability exists in Fiber v2 and v3 that allows remote attackers to crash the application by sending requests to routes with more than 30… |
| CVE-2025-66630 | Crítica (9.2) | 0.50% | — | 9 feb 2026 | Fiber is an Express inspired web framework written in Go. Before 2.52.11, on Go versions prior to 1.24, the underlying crypto/rand implementation can return an error if secure randomness cannot be obtained. Because no… |
| CVE-2025-54801 | Alta (8.7) | 0.37% | — | 6 ago 2025 | Fiber is an Express inspired web framework written in Go. In versions 2.52.8 and below, when using Fiber's Ctx.BodyParser to parse form data containing a large numeric key that represents a slice index (e.g.,… |
| CVE-2025-48075 | Alta (7.7) | 0.50% | — | 22 may 2025 | Fiber is an Express-inspired web framework written in Go. Starting in version 2.52.6 and prior to version 2.52.7, `fiber.Ctx.BodyParser` can map flat data to nested slices using `key[idx]value` syntax, but when idx is… |
| CVE-2024-38513 | Crítica (9.8) | 0.69% | — | 1 jul 2024 | Fiber is an Express-inspired web framework written in Go A vulnerability present in versions prior to 2.52.5 is a session middleware issue in GoFiber versions 2 and above. This vulnerability allows users to supply their… |
| CVE-2024-25124 | Crítica (9.8) | 0.66% | — | 21 feb 2024 | Fiber is a web framework written in go. Prior to version 2.52.1, the CORS middleware allows for insecure configurations that could potentially expose the application to multiple CORS-related vulnerabilities.… |
| CVE-2023-45141 | Alta (8.8) | 0.27% | — | 16 oct 2023 | Fiber is an express inspired web framework written in Go. A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the application, which allows an attacker to obtain tokens and forge malicious requests… |
| CVE-2023-45128 | Alta (8.8) | 0.31% | — | 16 oct 2023 | Fiber is an express inspired web framework written in Go. A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the application, which allows an attacker to inject arbitrary values and forge malicious… |
| CVE-2023-41338 | Media (5.3) | 0.66% | — | 8 sept 2023 | Fiber is an Express inspired web framework built in the go language. Versions of gofiber prior to 2.49.2 did not properly restrict access to localhost. This issue impacts users of our project who rely on the… |
| CVE-2020-15111 | Media (5.4) | 0.86% | — | 20 jul 2020 | In Fiber before version 1.12.6, the filename that is given in c.Attachment() (https://docs.gofiber.io/ctx#attachment) is not escaped, and therefore vulnerable for a CRLF injection attack. I.e. an attacker could upload a… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.