VendorsGofiberfiberany version
Vulnerabilities

Gofiber Fiber any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

17CVEs
CVE-2024-38513
Fiber Session Middleware Token Injection Vulnerability
Published 2024-07-01 · Analyzed
10.0EPSS 0.007
CVE-2023-45128
CSRF Token Reuse Vulnerability in fiber
Published 2023-10-16 · Modified
10.0EPSS 0.003
CVE-2024-25124
Fiber has Insecure CORS Configuration, Allowing Wildcard Origin with Credentials
Published 2024-02-21 · Analyzed
9.8EPSS 0.007
CVE-2025-66630
Fiber insecurely fallsback in utils.UUIDv4() / utils.UUID() — predictable / zero‑UUID on crypto/rand failure
Published 2026-02-09 · Analyzed
9.4EPSS 0.005
CVE-2023-45141
CSRF Token Validation Vulnerability in fiber
Published 2023-10-16 · Modified
8.8EPSS 0.003
CVE-2025-54801
Fiber Susceptible to Crash via `BodyParser` Due to Unvalidated Large Slice Index in Decoder
Published 2025-08-05 · Analyzed
8.7EPSS 0.004
CVE-2026-25891
Fiber has an Arbitrary File Read in Static Middleware on Windows
Published 2026-02-24 · Analyzed
7.7EPSS 0.007
CVE-2025-48075
Fiber panics when fiber.Ctx.BodyParser parses invalid range index
Published 2025-05-22 · Analyzed
7.7EPSS 0.005
CVE-2026-25882
Fiber has a Denial of Service Vulnerability via Route Parameter Overflow
Published 2026-02-24 · Analyzed
7.5EPSS 0.008
CVE-2026-25899
Fiber is Vulnerable to Denial of Service via Flash Cookie Unbounded Allocation
Published 2026-02-24 · Analyzed
7.5EPSS 0.006
CVE-2026-30246
github.com/gofiber/fiber/v3 cache middleware can mix responses across query parameters
Published 2026-05-05 · Analyzed
6.5EPSS 0.004
CVE-2026-42554
Fiber: XSS in AutoFormat Content Negotiation
Published 2026-05-11 · Analyzed
6.1EPSS 0.003
CVE-2020-15111
CRLF vulnerability in Fiber
Published 2020-07-20 · Modified
5.8EPSS 0.009
CVE-2023-41338
Vulnerability in Ctx.IsFromLocal() in gofiber
Published 2023-09-08 · Modified
5.3EPSS 0.007
CVE-2026-44332
Fiber: Username Enumeration via Timing Oracle in BasicAuth Default Authorizer
Published 2026-07-08 · Analyzed
5.3EPSS 0.005
CVE-2026-45045
Fiber: X-Real-IP Spoofing via Header.Add() in BalancerForward
Published 2026-07-08 · Analyzed
5.3EPSS 0.005
CVE-2026-53624
Fiber: HSTS header never set in helmet middleware due to incorrect protocol check
Published 2026-07-08 · Analyzed
4.8EPSS 0.002