github.com/gofiber/fiber/v2
⚡️ Express inspired web framework written in Go
Activity
- Latest release
- 1mo ago
- Total releases
- 61
- Cadence
- ~30 days
- Last 12 months
- 6
Reach
- Stars
- 40.1k
Details
- First release
- Sep 15, 2020
| Version | Released | |
|---|---|---|
v2.52.15
patch
|
v2.52.15
patch
Dependencies (8)
|
|
v2.52.14
patch
|
v2.52.14
patch
Dependencies (8)
|
|
v2.52.13
patch
1 CVE
CVE-2026-45045
GHSA-gcfq-8gqf-4876
GO-2026-5887
Jul 02, 2026
GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryThe Vulnerable CodeFile:
Data Flow
Impact
FixReplace
Fixed in
2.52.14
References
Updated Sep 10, 2026 · Source: OSV.dev |
v2.52.13
patch
Dependencies (8)
|
|
v2.52.12
patch
2 CVEs
CVE-2026-42554
GO-2026-5585
GHSA-qjv7-627w-8qjv
Jul 24, 2026
Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fixed in
2.52.13
Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-45045
GHSA-gcfq-8gqf-4876
GO-2026-5887
Jul 02, 2026
GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryThe Vulnerable CodeFile:
Data Flow
Impact
FixReplace
Fixed in
2.52.14
References
Updated Sep 10, 2026 · Source: OSV.dev |
v2.52.12
patch
Dependencies (8)
|
|
v2.52.11
patch
3 CVEs
CVE-2026-42554
GO-2026-5585
GHSA-qjv7-627w-8qjv
Jul 24, 2026
Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fixed in
2.52.13
Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-45045
GHSA-gcfq-8gqf-4876
GO-2026-5887
Jul 02, 2026
GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryThe Vulnerable CodeFile:
Data Flow
Impact
FixReplace
Fixed in
2.52.14
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25882
GO-2026-4543
GHSA-mrq8-rjmw-wpq3
Feb 26, 2026
Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fixed in
2.52.12
References Updated Feb 26, 2026 · Source: OSV.dev |
v2.52.11
patch
Dependencies (8)
|
|
v2.52.10
patch
4 CVEs
CVE-2026-42554
GO-2026-5585
GHSA-qjv7-627w-8qjv
Jul 24, 2026
Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fixed in
2.52.13
Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-45045
GHSA-gcfq-8gqf-4876
GO-2026-5887
Jul 02, 2026
GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryThe Vulnerable CodeFile:
Data Flow
Impact
FixReplace
Fixed in
2.52.14
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25882
GO-2026-4543
GHSA-mrq8-rjmw-wpq3
Feb 26, 2026
Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fixed in
2.52.12
References Updated Feb 26, 2026 · Source: OSV.dev
CVE-2025-66630
GO-2026-4471
GHSA-68rr-p4fp-j59v
Feb 19, 2026
Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() on crypto/rand failure in github.com/gofiber/fiber Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() — predictable / zero‑UUID on crypto/rand failure in github.com/gofiber/fiber Fixed in
2.52.11
References Updated Feb 19, 2026 · Source: OSV.dev |
v2.52.10
patch
Dependencies (8)
|
|
v2.52.9
patch
4 CVEs
CVE-2026-42554
GO-2026-5585
GHSA-qjv7-627w-8qjv
Jul 24, 2026
Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fixed in
2.52.13
Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-45045
GHSA-gcfq-8gqf-4876
GO-2026-5887
Jul 02, 2026
GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryThe Vulnerable CodeFile:
Data Flow
Impact
FixReplace
Fixed in
2.52.14
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25882
GO-2026-4543
GHSA-mrq8-rjmw-wpq3
Feb 26, 2026
Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fixed in
2.52.12
References Updated Feb 26, 2026 · Source: OSV.dev
CVE-2025-66630
GO-2026-4471
GHSA-68rr-p4fp-j59v
Feb 19, 2026
Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() on crypto/rand failure in github.com/gofiber/fiber Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() — predictable / zero‑UUID on crypto/rand failure in github.com/gofiber/fiber Fixed in
2.52.11
References Updated Feb 19, 2026 · Source: OSV.dev |
v2.52.9
patch
Dependencies (8)
|
|
v2.52.8
patch
5 CVEs
CVE-2026-42554
GO-2026-5585
GHSA-qjv7-627w-8qjv
Jul 24, 2026
Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fixed in
2.52.13
Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-45045
GHSA-gcfq-8gqf-4876
GO-2026-5887
Jul 02, 2026
GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryThe Vulnerable CodeFile:
Data Flow
Impact
FixReplace
Fixed in
2.52.14
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25882
GO-2026-4543
GHSA-mrq8-rjmw-wpq3
Feb 26, 2026
Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fixed in
2.52.12
References Updated Feb 26, 2026 · Source: OSV.dev
CVE-2025-66630
GO-2026-4471
GHSA-68rr-p4fp-j59v
Feb 19, 2026
Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() on crypto/rand failure in github.com/gofiber/fiber Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() — predictable / zero‑UUID on crypto/rand failure in github.com/gofiber/fiber Fixed in
2.52.11
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-54801
GO-2025-3845
GHSA-qx2q-88mx-vhg7
Aug 11, 2025
Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fixed in
2.52.9
References Updated Feb 04, 2026 · Source: OSV.dev |
v2.52.8
patch
Dependencies (8)
|
|
v2.52.7
patch
5 CVEs
CVE-2026-42554
GO-2026-5585
GHSA-qjv7-627w-8qjv
Jul 24, 2026
Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fixed in
2.52.13
Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-45045
GHSA-gcfq-8gqf-4876
GO-2026-5887
Jul 02, 2026
GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryThe Vulnerable CodeFile:
Data Flow
Impact
FixReplace
Fixed in
2.52.14
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25882
GO-2026-4543
GHSA-mrq8-rjmw-wpq3
Feb 26, 2026
Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fixed in
2.52.12
References Updated Feb 26, 2026 · Source: OSV.dev
CVE-2025-66630
GO-2026-4471
GHSA-68rr-p4fp-j59v
Feb 19, 2026
Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() on crypto/rand failure in github.com/gofiber/fiber Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() — predictable / zero‑UUID on crypto/rand failure in github.com/gofiber/fiber Fixed in
2.52.11
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-54801
GO-2025-3845
GHSA-qx2q-88mx-vhg7
Aug 11, 2025
Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fixed in
2.52.9
References Updated Feb 04, 2026 · Source: OSV.dev |
v2.52.7
patch
Dependencies (8)
|
|
v2.52.6
patch
6 CVEs
CVE-2026-42554
GO-2026-5585
GHSA-qjv7-627w-8qjv
Jul 24, 2026
Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fixed in
2.52.13
Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-45045
GHSA-gcfq-8gqf-4876
GO-2026-5887
Jul 02, 2026
GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryThe Vulnerable CodeFile:
Data Flow
Impact
FixReplace
Fixed in
2.52.14
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25882
GO-2026-4543
GHSA-mrq8-rjmw-wpq3
Feb 26, 2026
Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fixed in
2.52.12
References Updated Feb 26, 2026 · Source: OSV.dev
CVE-2025-66630
GO-2026-4471
GHSA-68rr-p4fp-j59v
Feb 19, 2026
Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() on crypto/rand failure in github.com/gofiber/fiber Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() — predictable / zero‑UUID on crypto/rand failure in github.com/gofiber/fiber Fixed in
2.52.11
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-54801
GO-2025-3845
GHSA-qx2q-88mx-vhg7
Aug 11, 2025
Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fixed in
2.52.9
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-48075
GO-2025-3706
GHSA-hg3g-gphw-5hhm
May 27, 2025
Fiber panics when fiber.Ctx.BodyParser parses invalid range index in github.com/gofiber/fiber Fiber panics when fiber.Ctx.BodyParser parses invalid range index in github.com/gofiber/fiber Fixed in
2.52.7
References Updated Feb 04, 2026 · Source: OSV.dev |
v2.52.6
patch
Dependencies (8)
|
|
v2.52.5
patch
5 CVEs
CVE-2026-42554
GO-2026-5585
GHSA-qjv7-627w-8qjv
Jul 24, 2026
Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fixed in
2.52.13
Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-45045
GHSA-gcfq-8gqf-4876
GO-2026-5887
Jul 02, 2026
GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryThe Vulnerable CodeFile:
Data Flow
Impact
FixReplace
Fixed in
2.52.14
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25882
GO-2026-4543
GHSA-mrq8-rjmw-wpq3
Feb 26, 2026
Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fixed in
2.52.12
References Updated Feb 26, 2026 · Source: OSV.dev
CVE-2025-66630
GO-2026-4471
GHSA-68rr-p4fp-j59v
Feb 19, 2026
Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() on crypto/rand failure in github.com/gofiber/fiber Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() — predictable / zero‑UUID on crypto/rand failure in github.com/gofiber/fiber Fixed in
2.52.11
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-54801
GO-2025-3845
GHSA-qx2q-88mx-vhg7
Aug 11, 2025
Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fixed in
2.52.9
References Updated Feb 04, 2026 · Source: OSV.dev |
v2.52.5
patch
Dependencies (8)
|
|
v2.52.4
patch
6 CVEs
CVE-2026-42554
GO-2026-5585
GHSA-qjv7-627w-8qjv
Jul 24, 2026
Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fixed in
2.52.13
Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-45045
GHSA-gcfq-8gqf-4876
GO-2026-5887
Jul 02, 2026
GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryThe Vulnerable CodeFile:
Data Flow
Impact
FixReplace
Fixed in
2.52.14
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25882
GO-2026-4543
GHSA-mrq8-rjmw-wpq3
Feb 26, 2026
Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fixed in
2.52.12
References Updated Feb 26, 2026 · Source: OSV.dev
CVE-2025-66630
GO-2026-4471
GHSA-68rr-p4fp-j59v
Feb 19, 2026
Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() on crypto/rand failure in github.com/gofiber/fiber Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() — predictable / zero‑UUID on crypto/rand failure in github.com/gofiber/fiber Fixed in
2.52.11
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-54801
GO-2025-3845
GHSA-qx2q-88mx-vhg7
Aug 11, 2025
Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fixed in
2.52.9
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-38513
GO-2024-2959
GHSA-98j2-3j3p-fw2v
Jul 02, 2024
Session Middleware Token Injection Vulnerability in github.com/gofiber/fiber Session Middleware Token Injection Vulnerability in github.com/gofiber/fiber Fixed in
2.52.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v2.52.4
patch
Dependencies (8)
|
|
v2.52.3
patch
6 CVEs
CVE-2026-42554
GO-2026-5585
GHSA-qjv7-627w-8qjv
Jul 24, 2026
Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fixed in
2.52.13
Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-45045
GHSA-gcfq-8gqf-4876
GO-2026-5887
Jul 02, 2026
GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryThe Vulnerable CodeFile:
Data Flow
Impact
FixReplace
Fixed in
2.52.14
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25882
GO-2026-4543
GHSA-mrq8-rjmw-wpq3
Feb 26, 2026
Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fixed in
2.52.12
References Updated Feb 26, 2026 · Source: OSV.dev
CVE-2025-66630
GO-2026-4471
GHSA-68rr-p4fp-j59v
Feb 19, 2026
Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() on crypto/rand failure in github.com/gofiber/fiber Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() — predictable / zero‑UUID on crypto/rand failure in github.com/gofiber/fiber Fixed in
2.52.11
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-54801
GO-2025-3845
GHSA-qx2q-88mx-vhg7
Aug 11, 2025
Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fixed in
2.52.9
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-38513
GO-2024-2959
GHSA-98j2-3j3p-fw2v
Jul 02, 2024
Session Middleware Token Injection Vulnerability in github.com/gofiber/fiber Session Middleware Token Injection Vulnerability in github.com/gofiber/fiber Fixed in
2.52.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v2.52.3
patch
Dependencies (8)
|
|
v2.52.2
patch
6 CVEs
CVE-2026-42554
GO-2026-5585
GHSA-qjv7-627w-8qjv
Jul 24, 2026
Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fixed in
2.52.13
Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-45045
GHSA-gcfq-8gqf-4876
GO-2026-5887
Jul 02, 2026
GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryThe Vulnerable CodeFile:
Data Flow
Impact
FixReplace
Fixed in
2.52.14
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25882
GO-2026-4543
GHSA-mrq8-rjmw-wpq3
Feb 26, 2026
Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fixed in
2.52.12
References Updated Feb 26, 2026 · Source: OSV.dev
CVE-2025-66630
GO-2026-4471
GHSA-68rr-p4fp-j59v
Feb 19, 2026
Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() on crypto/rand failure in github.com/gofiber/fiber Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() — predictable / zero‑UUID on crypto/rand failure in github.com/gofiber/fiber Fixed in
2.52.11
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-54801
GO-2025-3845
GHSA-qx2q-88mx-vhg7
Aug 11, 2025
Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fixed in
2.52.9
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-38513
GO-2024-2959
GHSA-98j2-3j3p-fw2v
Jul 02, 2024
Session Middleware Token Injection Vulnerability in github.com/gofiber/fiber Session Middleware Token Injection Vulnerability in github.com/gofiber/fiber Fixed in
2.52.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v2.52.2
patch
Dependencies (8)
|
|
v2.52.1
patch
6 CVEs
CVE-2026-42554
GO-2026-5585
GHSA-qjv7-627w-8qjv
Jul 24, 2026
Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fixed in
2.52.13
Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-45045
GHSA-gcfq-8gqf-4876
GO-2026-5887
Jul 02, 2026
GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryThe Vulnerable CodeFile:
Data Flow
Impact
FixReplace
Fixed in
2.52.14
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25882
GO-2026-4543
GHSA-mrq8-rjmw-wpq3
Feb 26, 2026
Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fixed in
2.52.12
References Updated Feb 26, 2026 · Source: OSV.dev
CVE-2025-66630
GO-2026-4471
GHSA-68rr-p4fp-j59v
Feb 19, 2026
Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() on crypto/rand failure in github.com/gofiber/fiber Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() — predictable / zero‑UUID on crypto/rand failure in github.com/gofiber/fiber Fixed in
2.52.11
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-54801
GO-2025-3845
GHSA-qx2q-88mx-vhg7
Aug 11, 2025
Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fixed in
2.52.9
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-38513
GO-2024-2959
GHSA-98j2-3j3p-fw2v
Jul 02, 2024
Session Middleware Token Injection Vulnerability in github.com/gofiber/fiber Session Middleware Token Injection Vulnerability in github.com/gofiber/fiber Fixed in
2.52.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v2.52.1
patch
Dependencies (8)
|
|
v2.52.0
minor
7 CVEs
CVE-2026-42554
GO-2026-5585
GHSA-qjv7-627w-8qjv
Jul 24, 2026
Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fixed in
2.52.13
Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-45045
GHSA-gcfq-8gqf-4876
GO-2026-5887
Jul 02, 2026
GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryThe Vulnerable CodeFile:
Data Flow
Impact
FixReplace
Fixed in
2.52.14
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25882
GO-2026-4543
GHSA-mrq8-rjmw-wpq3
Feb 26, 2026
Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fixed in
2.52.12
References Updated Feb 26, 2026 · Source: OSV.dev
CVE-2025-66630
GO-2026-4471
GHSA-68rr-p4fp-j59v
Feb 19, 2026
Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() on crypto/rand failure in github.com/gofiber/fiber Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() — predictable / zero‑UUID on crypto/rand failure in github.com/gofiber/fiber Fixed in
2.52.11
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-54801
GO-2025-3845
GHSA-qx2q-88mx-vhg7
Aug 11, 2025
Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fixed in
2.52.9
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-38513
GO-2024-2959
GHSA-98j2-3j3p-fw2v
Jul 02, 2024
Session Middleware Token Injection Vulnerability in github.com/gofiber/fiber Session Middleware Token Injection Vulnerability in github.com/gofiber/fiber Fixed in
2.52.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-25124
GO-2024-2574
GHSA-fmg4-x8pw-hjhg
May 20, 2024
Insecure CORS Configuration allowing wildcard origin with credentials in github.com/gofiber/fiber/v2 The CORS middleware allows for insecure configurations that could potentially expose the application to multiple CORS-related vulnerabilities. Specifically, it allows setting the Access-Control-Allow-Origin header to a wildcard ("*") while also having the Access-Control-Allow-Credentials set to true, which goes against recommended security best practices. Fixed in
2.52.1
References
Updated May 20, 2024 · Source: OSV.dev |
v2.52.0
minor
Dependencies (8)
|
|
v2.51.0
minor
7 CVEs
CVE-2026-42554
GO-2026-5585
GHSA-qjv7-627w-8qjv
Jul 24, 2026
Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fixed in
2.52.13
Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-45045
GHSA-gcfq-8gqf-4876
GO-2026-5887
Jul 02, 2026
GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryThe Vulnerable CodeFile:
Data Flow
Impact
FixReplace
Fixed in
2.52.14
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25882
GO-2026-4543
GHSA-mrq8-rjmw-wpq3
Feb 26, 2026
Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fixed in
2.52.12
References Updated Feb 26, 2026 · Source: OSV.dev
CVE-2025-66630
GO-2026-4471
GHSA-68rr-p4fp-j59v
Feb 19, 2026
Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() on crypto/rand failure in github.com/gofiber/fiber Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() — predictable / zero‑UUID on crypto/rand failure in github.com/gofiber/fiber Fixed in
2.52.11
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-54801
GO-2025-3845
GHSA-qx2q-88mx-vhg7
Aug 11, 2025
Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fixed in
2.52.9
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-38513
GO-2024-2959
GHSA-98j2-3j3p-fw2v
Jul 02, 2024
Session Middleware Token Injection Vulnerability in github.com/gofiber/fiber Session Middleware Token Injection Vulnerability in github.com/gofiber/fiber Fixed in
2.52.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-25124
GO-2024-2574
GHSA-fmg4-x8pw-hjhg
May 20, 2024
Insecure CORS Configuration allowing wildcard origin with credentials in github.com/gofiber/fiber/v2 The CORS middleware allows for insecure configurations that could potentially expose the application to multiple CORS-related vulnerabilities. Specifically, it allows setting the Access-Control-Allow-Origin header to a wildcard ("*") while also having the Access-Control-Allow-Credentials set to true, which goes against recommended security best practices. Fixed in
2.52.1
References
Updated May 20, 2024 · Source: OSV.dev |
v2.51.0
minor
Dependencies (8)
|
|
v2.50.0
minor
7 CVEs
CVE-2026-42554
GO-2026-5585
GHSA-qjv7-627w-8qjv
Jul 24, 2026
Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fixed in
2.52.13
Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-45045
GHSA-gcfq-8gqf-4876
GO-2026-5887
Jul 02, 2026
GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryThe Vulnerable CodeFile:
Data Flow
Impact
FixReplace
Fixed in
2.52.14
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25882
GO-2026-4543
GHSA-mrq8-rjmw-wpq3
Feb 26, 2026
Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fixed in
2.52.12
References Updated Feb 26, 2026 · Source: OSV.dev
CVE-2025-66630
GO-2026-4471
GHSA-68rr-p4fp-j59v
Feb 19, 2026
Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() on crypto/rand failure in github.com/gofiber/fiber Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() — predictable / zero‑UUID on crypto/rand failure in github.com/gofiber/fiber Fixed in
2.52.11
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-54801
GO-2025-3845
GHSA-qx2q-88mx-vhg7
Aug 11, 2025
Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fixed in
2.52.9
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-38513
GO-2024-2959
GHSA-98j2-3j3p-fw2v
Jul 02, 2024
Session Middleware Token Injection Vulnerability in github.com/gofiber/fiber Session Middleware Token Injection Vulnerability in github.com/gofiber/fiber Fixed in
2.52.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-25124
GO-2024-2574
GHSA-fmg4-x8pw-hjhg
May 20, 2024
Insecure CORS Configuration allowing wildcard origin with credentials in github.com/gofiber/fiber/v2 The CORS middleware allows for insecure configurations that could potentially expose the application to multiple CORS-related vulnerabilities. Specifically, it allows setting the Access-Control-Allow-Origin header to a wildcard ("*") while also having the Access-Control-Allow-Credentials set to true, which goes against recommended security best practices. Fixed in
2.52.1
References
Updated May 20, 2024 · Source: OSV.dev |
v2.50.0
minor
Dependencies (8)
|
|
v2.49.2
patch
9 CVEs
CVE-2026-42554
GO-2026-5585
GHSA-qjv7-627w-8qjv
Jul 24, 2026
Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fixed in
2.52.13
Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-45045
GHSA-gcfq-8gqf-4876
GO-2026-5887
Jul 02, 2026
GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryThe Vulnerable CodeFile:
Data Flow
Impact
FixReplace
Fixed in
2.52.14
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25882
GO-2026-4543
GHSA-mrq8-rjmw-wpq3
Feb 26, 2026
Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fixed in
2.52.12
References Updated Feb 26, 2026 · Source: OSV.dev
CVE-2025-66630
GO-2026-4471
GHSA-68rr-p4fp-j59v
Feb 19, 2026
Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() on crypto/rand failure in github.com/gofiber/fiber Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() — predictable / zero‑UUID on crypto/rand failure in github.com/gofiber/fiber Fixed in
2.52.11
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-54801
GO-2025-3845
GHSA-qx2q-88mx-vhg7
Aug 11, 2025
Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fixed in
2.52.9
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-38513
GO-2024-2959
GHSA-98j2-3j3p-fw2v
Jul 02, 2024
Session Middleware Token Injection Vulnerability in github.com/gofiber/fiber Session Middleware Token Injection Vulnerability in github.com/gofiber/fiber Fixed in
2.52.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-25124
GO-2024-2574
GHSA-fmg4-x8pw-hjhg
May 20, 2024
Insecure CORS Configuration allowing wildcard origin with credentials in github.com/gofiber/fiber/v2 The CORS middleware allows for insecure configurations that could potentially expose the application to multiple CORS-related vulnerabilities. Specifically, it allows setting the Access-Control-Allow-Origin header to a wildcard ("*") while also having the Access-Control-Allow-Credentials set to true, which goes against recommended security best practices. Fixed in
2.52.1
References
Updated May 20, 2024 · Source: OSV.dev
CVE-2023-45141
GO-2023-2116
GHSA-mv73-f69x-444p
Oct 24, 2023
CSRF token validation vulnerability in github.com/gofiber/fiber/v2 A cross-site request forgery vulnerability can allow an attacker to obtain tokens and forge malicious requests on behalf of a user. This can lead to unauthorized actions being taken on the user's behalf, potentially compromising the security and integrity of the application. The vulnerability is caused by improper validation and enforcement of CSRF tokens within the application. The CSRF token is validated against tokens in storage but was is not tied to the original requestor that generated it, allowing for token reuse. Fixed in
2.50.0
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-45128
GO-2023-2115
GHSA-94w9-97p3-p368
Oct 24, 2023
CSRF token reuse vulnerability in github.com/gofiber/fiber/v2 A cross-site request forgery vulnerability in this package can allow an attacker to inject arbitrary values and forge malicious requests on behalf of a user. The attacker may inject arbitrary values without any authentication, or perform various malicious actions on behalf of an authenticated user, potentially compromising the security and integrity of the application. The vulnerability is caused by improper validation and enforcement of CSRF tokens within the application. For 'safe' methods, the token is extracted from the cookie and saved to storage without further validation or sanitization. In addition, the CSRF token is validated against tokens in storage but not associated with a session, nor by using a Double Submit Cookie Method, allowing for token reuse. Fixed in
2.50.0
References Updated May 20, 2024 · Source: OSV.dev |
v2.49.2
patch
Dependencies (8)
|
|
v2.49.1
minor
10 CVEs
CVE-2026-42554
GO-2026-5585
GHSA-qjv7-627w-8qjv
Jul 24, 2026
Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fixed in
2.52.13
Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-45045
GHSA-gcfq-8gqf-4876
GO-2026-5887
Jul 02, 2026
GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryThe Vulnerable CodeFile:
Data Flow
Impact
FixReplace
Fixed in
2.52.14
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25882
GO-2026-4543
GHSA-mrq8-rjmw-wpq3
Feb 26, 2026
Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fixed in
2.52.12
References Updated Feb 26, 2026 · Source: OSV.dev
CVE-2025-66630
GO-2026-4471
GHSA-68rr-p4fp-j59v
Feb 19, 2026
Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() on crypto/rand failure in github.com/gofiber/fiber Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() — predictable / zero‑UUID on crypto/rand failure in github.com/gofiber/fiber Fixed in
2.52.11
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-54801
GO-2025-3845
GHSA-qx2q-88mx-vhg7
Aug 11, 2025
Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fixed in
2.52.9
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-38513
GO-2024-2959
GHSA-98j2-3j3p-fw2v
Jul 02, 2024
Session Middleware Token Injection Vulnerability in github.com/gofiber/fiber Session Middleware Token Injection Vulnerability in github.com/gofiber/fiber Fixed in
2.52.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-25124
GO-2024-2574
GHSA-fmg4-x8pw-hjhg
May 20, 2024
Insecure CORS Configuration allowing wildcard origin with credentials in github.com/gofiber/fiber/v2 The CORS middleware allows for insecure configurations that could potentially expose the application to multiple CORS-related vulnerabilities. Specifically, it allows setting the Access-Control-Allow-Origin header to a wildcard ("*") while also having the Access-Control-Allow-Credentials set to true, which goes against recommended security best practices. Fixed in
2.52.1
References
Updated May 20, 2024 · Source: OSV.dev
CVE-2023-45141
GO-2023-2116
GHSA-mv73-f69x-444p
Oct 24, 2023
CSRF token validation vulnerability in github.com/gofiber/fiber/v2 A cross-site request forgery vulnerability can allow an attacker to obtain tokens and forge malicious requests on behalf of a user. This can lead to unauthorized actions being taken on the user's behalf, potentially compromising the security and integrity of the application. The vulnerability is caused by improper validation and enforcement of CSRF tokens within the application. The CSRF token is validated against tokens in storage but was is not tied to the original requestor that generated it, allowing for token reuse. Fixed in
2.50.0
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-45128
GO-2023-2115
GHSA-94w9-97p3-p368
Oct 24, 2023
CSRF token reuse vulnerability in github.com/gofiber/fiber/v2 A cross-site request forgery vulnerability in this package can allow an attacker to inject arbitrary values and forge malicious requests on behalf of a user. The attacker may inject arbitrary values without any authentication, or perform various malicious actions on behalf of an authenticated user, potentially compromising the security and integrity of the application. The vulnerability is caused by improper validation and enforcement of CSRF tokens within the application. For 'safe' methods, the token is extracted from the cookie and saved to storage without further validation or sanitization. In addition, the CSRF token is validated against tokens in storage but not associated with a session, nor by using a Double Submit Cookie Method, allowing for token reuse. Fixed in
2.50.0
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-41338
GO-2023-2052
GHSA-3q5p-3558-364f
Sep 12, 2023
IsFromLocal local address check can be circumvented in github.com/gofiber/fiber/v2 The Ctx.IsFromLocal function can incorrectly report a request as being sent from localhost when the request contains an X-Forwarded-For header containing a localhost IP address. Fixed in
2.49.2-0.20230906112033-b8c9ede6efa2
References Updated May 20, 2024 · Source: OSV.dev |
v2.49.1
minor
Dependencies (8)
|
|
v2.48.0
minor
10 CVEs
CVE-2026-42554
GO-2026-5585
GHSA-qjv7-627w-8qjv
Jul 24, 2026
Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fixed in
2.52.13
Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-45045
GHSA-gcfq-8gqf-4876
GO-2026-5887
Jul 02, 2026
GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryThe Vulnerable CodeFile:
Data Flow
Impact
FixReplace
Fixed in
2.52.14
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25882
GO-2026-4543
GHSA-mrq8-rjmw-wpq3
Feb 26, 2026
Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fixed in
2.52.12
References Updated Feb 26, 2026 · Source: OSV.dev
CVE-2025-66630
GO-2026-4471
GHSA-68rr-p4fp-j59v
Feb 19, 2026
Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() on crypto/rand failure in github.com/gofiber/fiber Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() — predictable / zero‑UUID on crypto/rand failure in github.com/gofiber/fiber Fixed in
2.52.11
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-54801
GO-2025-3845
GHSA-qx2q-88mx-vhg7
Aug 11, 2025
Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fixed in
2.52.9
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-38513
GO-2024-2959
GHSA-98j2-3j3p-fw2v
Jul 02, 2024
Session Middleware Token Injection Vulnerability in github.com/gofiber/fiber Session Middleware Token Injection Vulnerability in github.com/gofiber/fiber Fixed in
2.52.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-25124
GO-2024-2574
GHSA-fmg4-x8pw-hjhg
May 20, 2024
Insecure CORS Configuration allowing wildcard origin with credentials in github.com/gofiber/fiber/v2 The CORS middleware allows for insecure configurations that could potentially expose the application to multiple CORS-related vulnerabilities. Specifically, it allows setting the Access-Control-Allow-Origin header to a wildcard ("*") while also having the Access-Control-Allow-Credentials set to true, which goes against recommended security best practices. Fixed in
2.52.1
References
Updated May 20, 2024 · Source: OSV.dev
CVE-2023-45141
GO-2023-2116
GHSA-mv73-f69x-444p
Oct 24, 2023
CSRF token validation vulnerability in github.com/gofiber/fiber/v2 A cross-site request forgery vulnerability can allow an attacker to obtain tokens and forge malicious requests on behalf of a user. This can lead to unauthorized actions being taken on the user's behalf, potentially compromising the security and integrity of the application. The vulnerability is caused by improper validation and enforcement of CSRF tokens within the application. The CSRF token is validated against tokens in storage but was is not tied to the original requestor that generated it, allowing for token reuse. Fixed in
2.50.0
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-45128
GO-2023-2115
GHSA-94w9-97p3-p368
Oct 24, 2023
CSRF token reuse vulnerability in github.com/gofiber/fiber/v2 A cross-site request forgery vulnerability in this package can allow an attacker to inject arbitrary values and forge malicious requests on behalf of a user. The attacker may inject arbitrary values without any authentication, or perform various malicious actions on behalf of an authenticated user, potentially compromising the security and integrity of the application. The vulnerability is caused by improper validation and enforcement of CSRF tokens within the application. For 'safe' methods, the token is extracted from the cookie and saved to storage without further validation or sanitization. In addition, the CSRF token is validated against tokens in storage but not associated with a session, nor by using a Double Submit Cookie Method, allowing for token reuse. Fixed in
2.50.0
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-41338
GO-2023-2052
GHSA-3q5p-3558-364f
Sep 12, 2023
IsFromLocal local address check can be circumvented in github.com/gofiber/fiber/v2 The Ctx.IsFromLocal function can incorrectly report a request as being sent from localhost when the request contains an X-Forwarded-For header containing a localhost IP address. Fixed in
2.49.2-0.20230906112033-b8c9ede6efa2
References Updated May 20, 2024 · Source: OSV.dev |
v2.48.0
minor
Dependencies (8)
|
|
v2.47.0
minor
10 CVEs
CVE-2026-42554
GO-2026-5585
GHSA-qjv7-627w-8qjv
Jul 24, 2026
Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fixed in
2.52.13
Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-45045
GHSA-gcfq-8gqf-4876
GO-2026-5887
Jul 02, 2026
GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryThe Vulnerable CodeFile:
Data Flow
Impact
FixReplace
Fixed in
2.52.14
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25882
GO-2026-4543
GHSA-mrq8-rjmw-wpq3
Feb 26, 2026
Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fixed in
2.52.12
References Updated Feb 26, 2026 · Source: OSV.dev
CVE-2025-66630
GO-2026-4471
GHSA-68rr-p4fp-j59v
Feb 19, 2026
Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() on crypto/rand failure in github.com/gofiber/fiber Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() — predictable / zero‑UUID on crypto/rand failure in github.com/gofiber/fiber Fixed in
2.52.11
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-54801
GO-2025-3845
GHSA-qx2q-88mx-vhg7
Aug 11, 2025
Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fixed in
2.52.9
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-38513
GO-2024-2959
GHSA-98j2-3j3p-fw2v
Jul 02, 2024
Session Middleware Token Injection Vulnerability in github.com/gofiber/fiber Session Middleware Token Injection Vulnerability in github.com/gofiber/fiber Fixed in
2.52.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-25124
GO-2024-2574
GHSA-fmg4-x8pw-hjhg
May 20, 2024
Insecure CORS Configuration allowing wildcard origin with credentials in github.com/gofiber/fiber/v2 The CORS middleware allows for insecure configurations that could potentially expose the application to multiple CORS-related vulnerabilities. Specifically, it allows setting the Access-Control-Allow-Origin header to a wildcard ("*") while also having the Access-Control-Allow-Credentials set to true, which goes against recommended security best practices. Fixed in
2.52.1
References
Updated May 20, 2024 · Source: OSV.dev
CVE-2023-45141
GO-2023-2116
GHSA-mv73-f69x-444p
Oct 24, 2023
CSRF token validation vulnerability in github.com/gofiber/fiber/v2 A cross-site request forgery vulnerability can allow an attacker to obtain tokens and forge malicious requests on behalf of a user. This can lead to unauthorized actions being taken on the user's behalf, potentially compromising the security and integrity of the application. The vulnerability is caused by improper validation and enforcement of CSRF tokens within the application. The CSRF token is validated against tokens in storage but was is not tied to the original requestor that generated it, allowing for token reuse. Fixed in
2.50.0
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-45128
GO-2023-2115
GHSA-94w9-97p3-p368
Oct 24, 2023
CSRF token reuse vulnerability in github.com/gofiber/fiber/v2 A cross-site request forgery vulnerability in this package can allow an attacker to inject arbitrary values and forge malicious requests on behalf of a user. The attacker may inject arbitrary values without any authentication, or perform various malicious actions on behalf of an authenticated user, potentially compromising the security and integrity of the application. The vulnerability is caused by improper validation and enforcement of CSRF tokens within the application. For 'safe' methods, the token is extracted from the cookie and saved to storage without further validation or sanitization. In addition, the CSRF token is validated against tokens in storage but not associated with a session, nor by using a Double Submit Cookie Method, allowing for token reuse. Fixed in
2.50.0
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-41338
GO-2023-2052
GHSA-3q5p-3558-364f
Sep 12, 2023
IsFromLocal local address check can be circumvented in github.com/gofiber/fiber/v2 The Ctx.IsFromLocal function can incorrectly report a request as being sent from localhost when the request contains an X-Forwarded-For header containing a localhost IP address. Fixed in
2.49.2-0.20230906112033-b8c9ede6efa2
References Updated May 20, 2024 · Source: OSV.dev |
v2.47.0
minor
Dependencies (9)
+ 1 more |
|
v2.46.0
minor
10 CVEs
CVE-2026-42554
GO-2026-5585
GHSA-qjv7-627w-8qjv
Jul 24, 2026
Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fixed in
2.52.13
Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-45045
GHSA-gcfq-8gqf-4876
GO-2026-5887
Jul 02, 2026
GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryThe Vulnerable CodeFile:
Data Flow
Impact
FixReplace
Fixed in
2.52.14
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25882
GO-2026-4543
GHSA-mrq8-rjmw-wpq3
Feb 26, 2026
Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fixed in
2.52.12
References Updated Feb 26, 2026 · Source: OSV.dev
CVE-2025-66630
GO-2026-4471
GHSA-68rr-p4fp-j59v
Feb 19, 2026
Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() on crypto/rand failure in github.com/gofiber/fiber Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() — predictable / zero‑UUID on crypto/rand failure in github.com/gofiber/fiber Fixed in
2.52.11
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-54801
GO-2025-3845
GHSA-qx2q-88mx-vhg7
Aug 11, 2025
Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fixed in
2.52.9
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-38513
GO-2024-2959
GHSA-98j2-3j3p-fw2v
Jul 02, 2024
Session Middleware Token Injection Vulnerability in github.com/gofiber/fiber Session Middleware Token Injection Vulnerability in github.com/gofiber/fiber Fixed in
2.52.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-25124
GO-2024-2574
GHSA-fmg4-x8pw-hjhg
May 20, 2024
Insecure CORS Configuration allowing wildcard origin with credentials in github.com/gofiber/fiber/v2 The CORS middleware allows for insecure configurations that could potentially expose the application to multiple CORS-related vulnerabilities. Specifically, it allows setting the Access-Control-Allow-Origin header to a wildcard ("*") while also having the Access-Control-Allow-Credentials set to true, which goes against recommended security best practices. Fixed in
2.52.1
References
Updated May 20, 2024 · Source: OSV.dev
CVE-2023-45141
GO-2023-2116
GHSA-mv73-f69x-444p
Oct 24, 2023
CSRF token validation vulnerability in github.com/gofiber/fiber/v2 A cross-site request forgery vulnerability can allow an attacker to obtain tokens and forge malicious requests on behalf of a user. This can lead to unauthorized actions being taken on the user's behalf, potentially compromising the security and integrity of the application. The vulnerability is caused by improper validation and enforcement of CSRF tokens within the application. The CSRF token is validated against tokens in storage but was is not tied to the original requestor that generated it, allowing for token reuse. Fixed in
2.50.0
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-45128
GO-2023-2115
GHSA-94w9-97p3-p368
Oct 24, 2023
CSRF token reuse vulnerability in github.com/gofiber/fiber/v2 A cross-site request forgery vulnerability in this package can allow an attacker to inject arbitrary values and forge malicious requests on behalf of a user. The attacker may inject arbitrary values without any authentication, or perform various malicious actions on behalf of an authenticated user, potentially compromising the security and integrity of the application. The vulnerability is caused by improper validation and enforcement of CSRF tokens within the application. For 'safe' methods, the token is extracted from the cookie and saved to storage without further validation or sanitization. In addition, the CSRF token is validated against tokens in storage but not associated with a session, nor by using a Double Submit Cookie Method, allowing for token reuse. Fixed in
2.50.0
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-41338
GO-2023-2052
GHSA-3q5p-3558-364f
Sep 12, 2023
IsFromLocal local address check can be circumvented in github.com/gofiber/fiber/v2 The Ctx.IsFromLocal function can incorrectly report a request as being sent from localhost when the request contains an X-Forwarded-For header containing a localhost IP address. Fixed in
2.49.2-0.20230906112033-b8c9ede6efa2
References Updated May 20, 2024 · Source: OSV.dev |
v2.46.0
minor
Dependencies (9)
+ 1 more |
|
v2.45.0
minor
10 CVEs
CVE-2026-42554
GO-2026-5585
GHSA-qjv7-627w-8qjv
Jul 24, 2026
Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fixed in
2.52.13
Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-45045
GHSA-gcfq-8gqf-4876
GO-2026-5887
Jul 02, 2026
GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryThe Vulnerable CodeFile:
Data Flow
Impact
FixReplace
Fixed in
2.52.14
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25882
GO-2026-4543
GHSA-mrq8-rjmw-wpq3
Feb 26, 2026
Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fixed in
2.52.12
References Updated Feb 26, 2026 · Source: OSV.dev
CVE-2025-66630
GO-2026-4471
GHSA-68rr-p4fp-j59v
Feb 19, 2026
Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() on crypto/rand failure in github.com/gofiber/fiber Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() — predictable / zero‑UUID on crypto/rand failure in github.com/gofiber/fiber Fixed in
2.52.11
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-54801
GO-2025-3845
GHSA-qx2q-88mx-vhg7
Aug 11, 2025
Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fixed in
2.52.9
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-38513
GO-2024-2959
GHSA-98j2-3j3p-fw2v
Jul 02, 2024
Session Middleware Token Injection Vulnerability in github.com/gofiber/fiber Session Middleware Token Injection Vulnerability in github.com/gofiber/fiber Fixed in
2.52.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-25124
GO-2024-2574
GHSA-fmg4-x8pw-hjhg
May 20, 2024
Insecure CORS Configuration allowing wildcard origin with credentials in github.com/gofiber/fiber/v2 The CORS middleware allows for insecure configurations that could potentially expose the application to multiple CORS-related vulnerabilities. Specifically, it allows setting the Access-Control-Allow-Origin header to a wildcard ("*") while also having the Access-Control-Allow-Credentials set to true, which goes against recommended security best practices. Fixed in
2.52.1
References
Updated May 20, 2024 · Source: OSV.dev
CVE-2023-45141
GO-2023-2116
GHSA-mv73-f69x-444p
Oct 24, 2023
CSRF token validation vulnerability in github.com/gofiber/fiber/v2 A cross-site request forgery vulnerability can allow an attacker to obtain tokens and forge malicious requests on behalf of a user. This can lead to unauthorized actions being taken on the user's behalf, potentially compromising the security and integrity of the application. The vulnerability is caused by improper validation and enforcement of CSRF tokens within the application. The CSRF token is validated against tokens in storage but was is not tied to the original requestor that generated it, allowing for token reuse. Fixed in
2.50.0
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-45128
GO-2023-2115
GHSA-94w9-97p3-p368
Oct 24, 2023
CSRF token reuse vulnerability in github.com/gofiber/fiber/v2 A cross-site request forgery vulnerability in this package can allow an attacker to inject arbitrary values and forge malicious requests on behalf of a user. The attacker may inject arbitrary values without any authentication, or perform various malicious actions on behalf of an authenticated user, potentially compromising the security and integrity of the application. The vulnerability is caused by improper validation and enforcement of CSRF tokens within the application. For 'safe' methods, the token is extracted from the cookie and saved to storage without further validation or sanitization. In addition, the CSRF token is validated against tokens in storage but not associated with a session, nor by using a Double Submit Cookie Method, allowing for token reuse. Fixed in
2.50.0
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-41338
GO-2023-2052
GHSA-3q5p-3558-364f
Sep 12, 2023
IsFromLocal local address check can be circumvented in github.com/gofiber/fiber/v2 The Ctx.IsFromLocal function can incorrectly report a request as being sent from localhost when the request contains an X-Forwarded-For header containing a localhost IP address. Fixed in
2.49.2-0.20230906112033-b8c9ede6efa2
References Updated May 20, 2024 · Source: OSV.dev |
v2.45.0
minor
Dependencies (9)
+ 1 more |
|
v2.44.0
minor
10 CVEs
CVE-2026-42554
GO-2026-5585
GHSA-qjv7-627w-8qjv
Jul 24, 2026
Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fixed in
2.52.13
Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-45045
GHSA-gcfq-8gqf-4876
GO-2026-5887
Jul 02, 2026
GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryThe Vulnerable CodeFile:
Data Flow
Impact
FixReplace
Fixed in
2.52.14
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25882
GO-2026-4543
GHSA-mrq8-rjmw-wpq3
Feb 26, 2026
Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fixed in
2.52.12
References Updated Feb 26, 2026 · Source: OSV.dev
CVE-2025-66630
GO-2026-4471
GHSA-68rr-p4fp-j59v
Feb 19, 2026
Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() on crypto/rand failure in github.com/gofiber/fiber Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() — predictable / zero‑UUID on crypto/rand failure in github.com/gofiber/fiber Fixed in
2.52.11
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-54801
GO-2025-3845
GHSA-qx2q-88mx-vhg7
Aug 11, 2025
Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fixed in
2.52.9
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-38513
GO-2024-2959
GHSA-98j2-3j3p-fw2v
Jul 02, 2024
Session Middleware Token Injection Vulnerability in github.com/gofiber/fiber Session Middleware Token Injection Vulnerability in github.com/gofiber/fiber Fixed in
2.52.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-25124
GO-2024-2574
GHSA-fmg4-x8pw-hjhg
May 20, 2024
Insecure CORS Configuration allowing wildcard origin with credentials in github.com/gofiber/fiber/v2 The CORS middleware allows for insecure configurations that could potentially expose the application to multiple CORS-related vulnerabilities. Specifically, it allows setting the Access-Control-Allow-Origin header to a wildcard ("*") while also having the Access-Control-Allow-Credentials set to true, which goes against recommended security best practices. Fixed in
2.52.1
References
Updated May 20, 2024 · Source: OSV.dev
CVE-2023-45141
GO-2023-2116
GHSA-mv73-f69x-444p
Oct 24, 2023
CSRF token validation vulnerability in github.com/gofiber/fiber/v2 A cross-site request forgery vulnerability can allow an attacker to obtain tokens and forge malicious requests on behalf of a user. This can lead to unauthorized actions being taken on the user's behalf, potentially compromising the security and integrity of the application. The vulnerability is caused by improper validation and enforcement of CSRF tokens within the application. The CSRF token is validated against tokens in storage but was is not tied to the original requestor that generated it, allowing for token reuse. Fixed in
2.50.0
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-45128
GO-2023-2115
GHSA-94w9-97p3-p368
Oct 24, 2023
CSRF token reuse vulnerability in github.com/gofiber/fiber/v2 A cross-site request forgery vulnerability in this package can allow an attacker to inject arbitrary values and forge malicious requests on behalf of a user. The attacker may inject arbitrary values without any authentication, or perform various malicious actions on behalf of an authenticated user, potentially compromising the security and integrity of the application. The vulnerability is caused by improper validation and enforcement of CSRF tokens within the application. For 'safe' methods, the token is extracted from the cookie and saved to storage without further validation or sanitization. In addition, the CSRF token is validated against tokens in storage but not associated with a session, nor by using a Double Submit Cookie Method, allowing for token reuse. Fixed in
2.50.0
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-41338
GO-2023-2052
GHSA-3q5p-3558-364f
Sep 12, 2023
IsFromLocal local address check can be circumvented in github.com/gofiber/fiber/v2 The Ctx.IsFromLocal function can incorrectly report a request as being sent from localhost when the request contains an X-Forwarded-For header containing a localhost IP address. Fixed in
2.49.2-0.20230906112033-b8c9ede6efa2
References Updated May 20, 2024 · Source: OSV.dev |
v2.44.0
minor
Dependencies (9)
+ 1 more |
|
v2.43.0
minor
10 CVEs
CVE-2026-42554
GO-2026-5585
GHSA-qjv7-627w-8qjv
Jul 24, 2026
Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fixed in
2.52.13
Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-45045
GHSA-gcfq-8gqf-4876
GO-2026-5887
Jul 02, 2026
GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryThe Vulnerable CodeFile:
Data Flow
Impact
FixReplace
Fixed in
2.52.14
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25882
GO-2026-4543
GHSA-mrq8-rjmw-wpq3
Feb 26, 2026
Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fixed in
2.52.12
References Updated Feb 26, 2026 · Source: OSV.dev
CVE-2025-66630
GO-2026-4471
GHSA-68rr-p4fp-j59v
Feb 19, 2026
Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() on crypto/rand failure in github.com/gofiber/fiber Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() — predictable / zero‑UUID on crypto/rand failure in github.com/gofiber/fiber Fixed in
2.52.11
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-54801
GO-2025-3845
GHSA-qx2q-88mx-vhg7
Aug 11, 2025
Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fixed in
2.52.9
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-38513
GO-2024-2959
GHSA-98j2-3j3p-fw2v
Jul 02, 2024
Session Middleware Token Injection Vulnerability in github.com/gofiber/fiber Session Middleware Token Injection Vulnerability in github.com/gofiber/fiber Fixed in
2.52.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-25124
GO-2024-2574
GHSA-fmg4-x8pw-hjhg
May 20, 2024
Insecure CORS Configuration allowing wildcard origin with credentials in github.com/gofiber/fiber/v2 The CORS middleware allows for insecure configurations that could potentially expose the application to multiple CORS-related vulnerabilities. Specifically, it allows setting the Access-Control-Allow-Origin header to a wildcard ("*") while also having the Access-Control-Allow-Credentials set to true, which goes against recommended security best practices. Fixed in
2.52.1
References
Updated May 20, 2024 · Source: OSV.dev
CVE-2023-45141
GO-2023-2116
GHSA-mv73-f69x-444p
Oct 24, 2023
CSRF token validation vulnerability in github.com/gofiber/fiber/v2 A cross-site request forgery vulnerability can allow an attacker to obtain tokens and forge malicious requests on behalf of a user. This can lead to unauthorized actions being taken on the user's behalf, potentially compromising the security and integrity of the application. The vulnerability is caused by improper validation and enforcement of CSRF tokens within the application. The CSRF token is validated against tokens in storage but was is not tied to the original requestor that generated it, allowing for token reuse. Fixed in
2.50.0
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-45128
GO-2023-2115
GHSA-94w9-97p3-p368
Oct 24, 2023
CSRF token reuse vulnerability in github.com/gofiber/fiber/v2 A cross-site request forgery vulnerability in this package can allow an attacker to inject arbitrary values and forge malicious requests on behalf of a user. The attacker may inject arbitrary values without any authentication, or perform various malicious actions on behalf of an authenticated user, potentially compromising the security and integrity of the application. The vulnerability is caused by improper validation and enforcement of CSRF tokens within the application. For 'safe' methods, the token is extracted from the cookie and saved to storage without further validation or sanitization. In addition, the CSRF token is validated against tokens in storage but not associated with a session, nor by using a Double Submit Cookie Method, allowing for token reuse. Fixed in
2.50.0
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-41338
GO-2023-2052
GHSA-3q5p-3558-364f
Sep 12, 2023
IsFromLocal local address check can be circumvented in github.com/gofiber/fiber/v2 The Ctx.IsFromLocal function can incorrectly report a request as being sent from localhost when the request contains an X-Forwarded-For header containing a localhost IP address. Fixed in
2.49.2-0.20230906112033-b8c9ede6efa2
References Updated May 20, 2024 · Source: OSV.dev |
v2.43.0
minor
Dependencies (9)
+ 1 more |
|
v2.41.0
minor
11 CVEs
CVE-2026-42554
GO-2026-5585
GHSA-qjv7-627w-8qjv
Jul 24, 2026
Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fixed in
2.52.13
Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-45045
GHSA-gcfq-8gqf-4876
GO-2026-5887
Jul 02, 2026
GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryThe Vulnerable CodeFile:
Data Flow
Impact
FixReplace
Fixed in
2.52.14
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25882
GO-2026-4543
GHSA-mrq8-rjmw-wpq3
Feb 26, 2026
Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fixed in
2.52.12
References Updated Feb 26, 2026 · Source: OSV.dev
CVE-2025-66630
GO-2026-4471
GHSA-68rr-p4fp-j59v
Feb 19, 2026
Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() on crypto/rand failure in github.com/gofiber/fiber Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() — predictable / zero‑UUID on crypto/rand failure in github.com/gofiber/fiber Fixed in
2.52.11
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-54801
GO-2025-3845
GHSA-qx2q-88mx-vhg7
Aug 11, 2025
Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fixed in
2.52.9
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-38513
GO-2024-2959
GHSA-98j2-3j3p-fw2v
Jul 02, 2024
Session Middleware Token Injection Vulnerability in github.com/gofiber/fiber Session Middleware Token Injection Vulnerability in github.com/gofiber/fiber Fixed in
2.52.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-25124
GO-2024-2574
GHSA-fmg4-x8pw-hjhg
May 20, 2024
Insecure CORS Configuration allowing wildcard origin with credentials in github.com/gofiber/fiber/v2 The CORS middleware allows for insecure configurations that could potentially expose the application to multiple CORS-related vulnerabilities. Specifically, it allows setting the Access-Control-Allow-Origin header to a wildcard ("*") while also having the Access-Control-Allow-Credentials set to true, which goes against recommended security best practices. Fixed in
2.52.1
References
Updated May 20, 2024 · Source: OSV.dev
CVE-2023-45141
GO-2023-2116
GHSA-mv73-f69x-444p
Oct 24, 2023
CSRF token validation vulnerability in github.com/gofiber/fiber/v2 A cross-site request forgery vulnerability can allow an attacker to obtain tokens and forge malicious requests on behalf of a user. This can lead to unauthorized actions being taken on the user's behalf, potentially compromising the security and integrity of the application. The vulnerability is caused by improper validation and enforcement of CSRF tokens within the application. The CSRF token is validated against tokens in storage but was is not tied to the original requestor that generated it, allowing for token reuse. Fixed in
2.50.0
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-45128
GO-2023-2115
GHSA-94w9-97p3-p368
Oct 24, 2023
CSRF token reuse vulnerability in github.com/gofiber/fiber/v2 A cross-site request forgery vulnerability in this package can allow an attacker to inject arbitrary values and forge malicious requests on behalf of a user. The attacker may inject arbitrary values without any authentication, or perform various malicious actions on behalf of an authenticated user, potentially compromising the security and integrity of the application. The vulnerability is caused by improper validation and enforcement of CSRF tokens within the application. For 'safe' methods, the token is extracted from the cookie and saved to storage without further validation or sanitization. In addition, the CSRF token is validated against tokens in storage but not associated with a session, nor by using a Double Submit Cookie Method, allowing for token reuse. Fixed in
2.50.0
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-41338
GO-2023-2052
GHSA-3q5p-3558-364f
Sep 12, 2023
IsFromLocal local address check can be circumvented in github.com/gofiber/fiber/v2 The Ctx.IsFromLocal function can incorrectly report a request as being sent from localhost when the request contains an X-Forwarded-For header containing a localhost IP address. Fixed in
2.49.2-0.20230906112033-b8c9ede6efa2
References Updated May 20, 2024 · Source: OSV.dev
CVE-2018-20744
GHSA-927h-x4qj-r242
GO-2023-1792
May 14, 2022
github.com/gofiber/fiber/v2 vulnerable to Origin Validation Error
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
The Olivier Poitrey Go CORS handler through 1.3.0 actively converts a wildcard CORS policy into reflecting an arbitrary Origin header value, which is incompatible with the CORS security design, and could lead to CORS misconfiguration security problems. Fixed in
2.43.0
References Updated May 20, 2024 · Source: OSV.dev |
v2.41.0
minor
Dependencies (6)
|
|
v2.40.0
minor
11 CVEs
CVE-2026-42554
GO-2026-5585
GHSA-qjv7-627w-8qjv
Jul 24, 2026
Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fixed in
2.52.13
Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-45045
GHSA-gcfq-8gqf-4876
GO-2026-5887
Jul 02, 2026
GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryThe Vulnerable CodeFile:
Data Flow
Impact
FixReplace
Fixed in
2.52.14
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25882
GO-2026-4543
GHSA-mrq8-rjmw-wpq3
Feb 26, 2026
Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fixed in
2.52.12
References Updated Feb 26, 2026 · Source: OSV.dev
CVE-2025-66630
GO-2026-4471
GHSA-68rr-p4fp-j59v
Feb 19, 2026
Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() on crypto/rand failure in github.com/gofiber/fiber Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() — predictable / zero‑UUID on crypto/rand failure in github.com/gofiber/fiber Fixed in
2.52.11
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-54801
GO-2025-3845
GHSA-qx2q-88mx-vhg7
Aug 11, 2025
Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fixed in
2.52.9
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-38513
GO-2024-2959
GHSA-98j2-3j3p-fw2v
Jul 02, 2024
Session Middleware Token Injection Vulnerability in github.com/gofiber/fiber Session Middleware Token Injection Vulnerability in github.com/gofiber/fiber Fixed in
2.52.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-25124
GO-2024-2574
GHSA-fmg4-x8pw-hjhg
May 20, 2024
Insecure CORS Configuration allowing wildcard origin with credentials in github.com/gofiber/fiber/v2 The CORS middleware allows for insecure configurations that could potentially expose the application to multiple CORS-related vulnerabilities. Specifically, it allows setting the Access-Control-Allow-Origin header to a wildcard ("*") while also having the Access-Control-Allow-Credentials set to true, which goes against recommended security best practices. Fixed in
2.52.1
References
Updated May 20, 2024 · Source: OSV.dev
CVE-2023-45141
GO-2023-2116
GHSA-mv73-f69x-444p
Oct 24, 2023
CSRF token validation vulnerability in github.com/gofiber/fiber/v2 A cross-site request forgery vulnerability can allow an attacker to obtain tokens and forge malicious requests on behalf of a user. This can lead to unauthorized actions being taken on the user's behalf, potentially compromising the security and integrity of the application. The vulnerability is caused by improper validation and enforcement of CSRF tokens within the application. The CSRF token is validated against tokens in storage but was is not tied to the original requestor that generated it, allowing for token reuse. Fixed in
2.50.0
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-45128
GO-2023-2115
GHSA-94w9-97p3-p368
Oct 24, 2023
CSRF token reuse vulnerability in github.com/gofiber/fiber/v2 A cross-site request forgery vulnerability in this package can allow an attacker to inject arbitrary values and forge malicious requests on behalf of a user. The attacker may inject arbitrary values without any authentication, or perform various malicious actions on behalf of an authenticated user, potentially compromising the security and integrity of the application. The vulnerability is caused by improper validation and enforcement of CSRF tokens within the application. For 'safe' methods, the token is extracted from the cookie and saved to storage without further validation or sanitization. In addition, the CSRF token is validated against tokens in storage but not associated with a session, nor by using a Double Submit Cookie Method, allowing for token reuse. Fixed in
2.50.0
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-41338
GO-2023-2052
GHSA-3q5p-3558-364f
Sep 12, 2023
IsFromLocal local address check can be circumvented in github.com/gofiber/fiber/v2 The Ctx.IsFromLocal function can incorrectly report a request as being sent from localhost when the request contains an X-Forwarded-For header containing a localhost IP address. Fixed in
2.49.2-0.20230906112033-b8c9ede6efa2
References Updated May 20, 2024 · Source: OSV.dev
CVE-2018-20744
GHSA-927h-x4qj-r242
GO-2023-1792
May 14, 2022
github.com/gofiber/fiber/v2 vulnerable to Origin Validation Error
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
The Olivier Poitrey Go CORS handler through 1.3.0 actively converts a wildcard CORS policy into reflecting an arbitrary Origin header value, which is incompatible with the CORS security design, and could lead to CORS misconfiguration security problems. Fixed in
2.43.0
References Updated May 20, 2024 · Source: OSV.dev |
v2.40.0
minor
Dependencies (6)
|
|
v2.39.0
minor
11 CVEs
CVE-2026-42554
GO-2026-5585
GHSA-qjv7-627w-8qjv
Jul 24, 2026
Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fixed in
2.52.13
Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-45045
GHSA-gcfq-8gqf-4876
GO-2026-5887
Jul 02, 2026
GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryThe Vulnerable CodeFile:
Data Flow
Impact
FixReplace
Fixed in
2.52.14
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25882
GO-2026-4543
GHSA-mrq8-rjmw-wpq3
Feb 26, 2026
Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fixed in
2.52.12
References Updated Feb 26, 2026 · Source: OSV.dev
CVE-2025-66630
GO-2026-4471
GHSA-68rr-p4fp-j59v
Feb 19, 2026
Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() on crypto/rand failure in github.com/gofiber/fiber Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() — predictable / zero‑UUID on crypto/rand failure in github.com/gofiber/fiber Fixed in
2.52.11
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-54801
GO-2025-3845
GHSA-qx2q-88mx-vhg7
Aug 11, 2025
Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fixed in
2.52.9
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-38513
GO-2024-2959
GHSA-98j2-3j3p-fw2v
Jul 02, 2024
Session Middleware Token Injection Vulnerability in github.com/gofiber/fiber Session Middleware Token Injection Vulnerability in github.com/gofiber/fiber Fixed in
2.52.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-25124
GO-2024-2574
GHSA-fmg4-x8pw-hjhg
May 20, 2024
Insecure CORS Configuration allowing wildcard origin with credentials in github.com/gofiber/fiber/v2 The CORS middleware allows for insecure configurations that could potentially expose the application to multiple CORS-related vulnerabilities. Specifically, it allows setting the Access-Control-Allow-Origin header to a wildcard ("*") while also having the Access-Control-Allow-Credentials set to true, which goes against recommended security best practices. Fixed in
2.52.1
References
Updated May 20, 2024 · Source: OSV.dev
CVE-2023-45141
GO-2023-2116
GHSA-mv73-f69x-444p
Oct 24, 2023
CSRF token validation vulnerability in github.com/gofiber/fiber/v2 A cross-site request forgery vulnerability can allow an attacker to obtain tokens and forge malicious requests on behalf of a user. This can lead to unauthorized actions being taken on the user's behalf, potentially compromising the security and integrity of the application. The vulnerability is caused by improper validation and enforcement of CSRF tokens within the application. The CSRF token is validated against tokens in storage but was is not tied to the original requestor that generated it, allowing for token reuse. Fixed in
2.50.0
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-45128
GO-2023-2115
GHSA-94w9-97p3-p368
Oct 24, 2023
CSRF token reuse vulnerability in github.com/gofiber/fiber/v2 A cross-site request forgery vulnerability in this package can allow an attacker to inject arbitrary values and forge malicious requests on behalf of a user. The attacker may inject arbitrary values without any authentication, or perform various malicious actions on behalf of an authenticated user, potentially compromising the security and integrity of the application. The vulnerability is caused by improper validation and enforcement of CSRF tokens within the application. For 'safe' methods, the token is extracted from the cookie and saved to storage without further validation or sanitization. In addition, the CSRF token is validated against tokens in storage but not associated with a session, nor by using a Double Submit Cookie Method, allowing for token reuse. Fixed in
2.50.0
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-41338
GO-2023-2052
GHSA-3q5p-3558-364f
Sep 12, 2023
IsFromLocal local address check can be circumvented in github.com/gofiber/fiber/v2 The Ctx.IsFromLocal function can incorrectly report a request as being sent from localhost when the request contains an X-Forwarded-For header containing a localhost IP address. Fixed in
2.49.2-0.20230906112033-b8c9ede6efa2
References Updated May 20, 2024 · Source: OSV.dev
CVE-2018-20744
GHSA-927h-x4qj-r242
GO-2023-1792
May 14, 2022
github.com/gofiber/fiber/v2 vulnerable to Origin Validation Error
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
The Olivier Poitrey Go CORS handler through 1.3.0 actively converts a wildcard CORS policy into reflecting an arbitrary Origin header value, which is incompatible with the CORS security design, and could lead to CORS misconfiguration security problems. Fixed in
2.43.0
References Updated May 20, 2024 · Source: OSV.dev |
v2.39.0
minor
Dependencies (5)
|
|
v2.37.1
minor
11 CVEs
CVE-2026-42554
GO-2026-5585
GHSA-qjv7-627w-8qjv
Jul 24, 2026
Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fixed in
2.52.13
Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-45045
GHSA-gcfq-8gqf-4876
GO-2026-5887
Jul 02, 2026
GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryThe Vulnerable CodeFile:
Data Flow
Impact
FixReplace
Fixed in
2.52.14
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25882
GO-2026-4543
GHSA-mrq8-rjmw-wpq3
Feb 26, 2026
Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fixed in
2.52.12
References Updated Feb 26, 2026 · Source: OSV.dev
CVE-2025-66630
GO-2026-4471
GHSA-68rr-p4fp-j59v
Feb 19, 2026
Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() on crypto/rand failure in github.com/gofiber/fiber Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() — predictable / zero‑UUID on crypto/rand failure in github.com/gofiber/fiber Fixed in
2.52.11
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-54801
GO-2025-3845
GHSA-qx2q-88mx-vhg7
Aug 11, 2025
Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fixed in
2.52.9
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-38513
GO-2024-2959
GHSA-98j2-3j3p-fw2v
Jul 02, 2024
Session Middleware Token Injection Vulnerability in github.com/gofiber/fiber Session Middleware Token Injection Vulnerability in github.com/gofiber/fiber Fixed in
2.52.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-25124
GO-2024-2574
GHSA-fmg4-x8pw-hjhg
May 20, 2024
Insecure CORS Configuration allowing wildcard origin with credentials in github.com/gofiber/fiber/v2 The CORS middleware allows for insecure configurations that could potentially expose the application to multiple CORS-related vulnerabilities. Specifically, it allows setting the Access-Control-Allow-Origin header to a wildcard ("*") while also having the Access-Control-Allow-Credentials set to true, which goes against recommended security best practices. Fixed in
2.52.1
References
Updated May 20, 2024 · Source: OSV.dev
CVE-2023-45141
GO-2023-2116
GHSA-mv73-f69x-444p
Oct 24, 2023
CSRF token validation vulnerability in github.com/gofiber/fiber/v2 A cross-site request forgery vulnerability can allow an attacker to obtain tokens and forge malicious requests on behalf of a user. This can lead to unauthorized actions being taken on the user's behalf, potentially compromising the security and integrity of the application. The vulnerability is caused by improper validation and enforcement of CSRF tokens within the application. The CSRF token is validated against tokens in storage but was is not tied to the original requestor that generated it, allowing for token reuse. Fixed in
2.50.0
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-45128
GO-2023-2115
GHSA-94w9-97p3-p368
Oct 24, 2023
CSRF token reuse vulnerability in github.com/gofiber/fiber/v2 A cross-site request forgery vulnerability in this package can allow an attacker to inject arbitrary values and forge malicious requests on behalf of a user. The attacker may inject arbitrary values without any authentication, or perform various malicious actions on behalf of an authenticated user, potentially compromising the security and integrity of the application. The vulnerability is caused by improper validation and enforcement of CSRF tokens within the application. For 'safe' methods, the token is extracted from the cookie and saved to storage without further validation or sanitization. In addition, the CSRF token is validated against tokens in storage but not associated with a session, nor by using a Double Submit Cookie Method, allowing for token reuse. Fixed in
2.50.0
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-41338
GO-2023-2052
GHSA-3q5p-3558-364f
Sep 12, 2023
IsFromLocal local address check can be circumvented in github.com/gofiber/fiber/v2 The Ctx.IsFromLocal function can incorrectly report a request as being sent from localhost when the request contains an X-Forwarded-For header containing a localhost IP address. Fixed in
2.49.2-0.20230906112033-b8c9ede6efa2
References Updated May 20, 2024 · Source: OSV.dev
CVE-2018-20744
GHSA-927h-x4qj-r242
GO-2023-1792
May 14, 2022
github.com/gofiber/fiber/v2 vulnerable to Origin Validation Error
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
The Olivier Poitrey Go CORS handler through 1.3.0 actively converts a wildcard CORS policy into reflecting an arbitrary Origin header value, which is incompatible with the CORS security design, and could lead to CORS misconfiguration security problems. Fixed in
2.43.0
References Updated May 20, 2024 · Source: OSV.dev |
v2.37.1
minor
Dependencies (2)
|
|
v2.34.1
minor
11 CVEs
CVE-2026-42554
GO-2026-5585
GHSA-qjv7-627w-8qjv
Jul 24, 2026
Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fixed in
2.52.13
Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-45045
GHSA-gcfq-8gqf-4876
GO-2026-5887
Jul 02, 2026
GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryThe Vulnerable CodeFile:
Data Flow
Impact
FixReplace
Fixed in
2.52.14
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25882
GO-2026-4543
GHSA-mrq8-rjmw-wpq3
Feb 26, 2026
Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fixed in
2.52.12
References Updated Feb 26, 2026 · Source: OSV.dev
CVE-2025-66630
GO-2026-4471
GHSA-68rr-p4fp-j59v
Feb 19, 2026
Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() on crypto/rand failure in github.com/gofiber/fiber Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() — predictable / zero‑UUID on crypto/rand failure in github.com/gofiber/fiber Fixed in
2.52.11
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-54801
GO-2025-3845
GHSA-qx2q-88mx-vhg7
Aug 11, 2025
Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fixed in
2.52.9
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-38513
GO-2024-2959
GHSA-98j2-3j3p-fw2v
Jul 02, 2024
Session Middleware Token Injection Vulnerability in github.com/gofiber/fiber Session Middleware Token Injection Vulnerability in github.com/gofiber/fiber Fixed in
2.52.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-25124
GO-2024-2574
GHSA-fmg4-x8pw-hjhg
May 20, 2024
Insecure CORS Configuration allowing wildcard origin with credentials in github.com/gofiber/fiber/v2 The CORS middleware allows for insecure configurations that could potentially expose the application to multiple CORS-related vulnerabilities. Specifically, it allows setting the Access-Control-Allow-Origin header to a wildcard ("*") while also having the Access-Control-Allow-Credentials set to true, which goes against recommended security best practices. Fixed in
2.52.1
References
Updated May 20, 2024 · Source: OSV.dev
CVE-2023-45141
GO-2023-2116
GHSA-mv73-f69x-444p
Oct 24, 2023
CSRF token validation vulnerability in github.com/gofiber/fiber/v2 A cross-site request forgery vulnerability can allow an attacker to obtain tokens and forge malicious requests on behalf of a user. This can lead to unauthorized actions being taken on the user's behalf, potentially compromising the security and integrity of the application. The vulnerability is caused by improper validation and enforcement of CSRF tokens within the application. The CSRF token is validated against tokens in storage but was is not tied to the original requestor that generated it, allowing for token reuse. Fixed in
2.50.0
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-45128
GO-2023-2115
GHSA-94w9-97p3-p368
Oct 24, 2023
CSRF token reuse vulnerability in github.com/gofiber/fiber/v2 A cross-site request forgery vulnerability in this package can allow an attacker to inject arbitrary values and forge malicious requests on behalf of a user. The attacker may inject arbitrary values without any authentication, or perform various malicious actions on behalf of an authenticated user, potentially compromising the security and integrity of the application. The vulnerability is caused by improper validation and enforcement of CSRF tokens within the application. For 'safe' methods, the token is extracted from the cookie and saved to storage without further validation or sanitization. In addition, the CSRF token is validated against tokens in storage but not associated with a session, nor by using a Double Submit Cookie Method, allowing for token reuse. Fixed in
2.50.0
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-41338
GO-2023-2052
GHSA-3q5p-3558-364f
Sep 12, 2023
IsFromLocal local address check can be circumvented in github.com/gofiber/fiber/v2 The Ctx.IsFromLocal function can incorrectly report a request as being sent from localhost when the request contains an X-Forwarded-For header containing a localhost IP address. Fixed in
2.49.2-0.20230906112033-b8c9ede6efa2
References Updated May 20, 2024 · Source: OSV.dev
CVE-2018-20744
GHSA-927h-x4qj-r242
GO-2023-1792
May 14, 2022
github.com/gofiber/fiber/v2 vulnerable to Origin Validation Error
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
The Olivier Poitrey Go CORS handler through 1.3.0 actively converts a wildcard CORS policy into reflecting an arbitrary Origin header value, which is incompatible with the CORS security design, and could lead to CORS misconfiguration security problems. Fixed in
2.43.0
References Updated May 20, 2024 · Source: OSV.dev |
v2.34.1
minor
Dependencies (2)
|
|
v2.32.0
minor
11 CVEs
CVE-2026-42554
GO-2026-5585
GHSA-qjv7-627w-8qjv
Jul 24, 2026
Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fixed in
2.52.13
Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-45045
GHSA-gcfq-8gqf-4876
GO-2026-5887
Jul 02, 2026
GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryThe Vulnerable CodeFile:
Data Flow
Impact
FixReplace
Fixed in
2.52.14
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25882
GO-2026-4543
GHSA-mrq8-rjmw-wpq3
Feb 26, 2026
Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fixed in
2.52.12
References Updated Feb 26, 2026 · Source: OSV.dev
CVE-2025-66630
GO-2026-4471
GHSA-68rr-p4fp-j59v
Feb 19, 2026
Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() on crypto/rand failure in github.com/gofiber/fiber Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() — predictable / zero‑UUID on crypto/rand failure in github.com/gofiber/fiber Fixed in
2.52.11
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-54801
GO-2025-3845
GHSA-qx2q-88mx-vhg7
Aug 11, 2025
Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fixed in
2.52.9
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-38513
GO-2024-2959
GHSA-98j2-3j3p-fw2v
Jul 02, 2024
Session Middleware Token Injection Vulnerability in github.com/gofiber/fiber Session Middleware Token Injection Vulnerability in github.com/gofiber/fiber Fixed in
2.52.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-25124
GO-2024-2574
GHSA-fmg4-x8pw-hjhg
May 20, 2024
Insecure CORS Configuration allowing wildcard origin with credentials in github.com/gofiber/fiber/v2 The CORS middleware allows for insecure configurations that could potentially expose the application to multiple CORS-related vulnerabilities. Specifically, it allows setting the Access-Control-Allow-Origin header to a wildcard ("*") while also having the Access-Control-Allow-Credentials set to true, which goes against recommended security best practices. Fixed in
2.52.1
References
Updated May 20, 2024 · Source: OSV.dev
CVE-2023-45141
GO-2023-2116
GHSA-mv73-f69x-444p
Oct 24, 2023
CSRF token validation vulnerability in github.com/gofiber/fiber/v2 A cross-site request forgery vulnerability can allow an attacker to obtain tokens and forge malicious requests on behalf of a user. This can lead to unauthorized actions being taken on the user's behalf, potentially compromising the security and integrity of the application. The vulnerability is caused by improper validation and enforcement of CSRF tokens within the application. The CSRF token is validated against tokens in storage but was is not tied to the original requestor that generated it, allowing for token reuse. Fixed in
2.50.0
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-45128
GO-2023-2115
GHSA-94w9-97p3-p368
Oct 24, 2023
CSRF token reuse vulnerability in github.com/gofiber/fiber/v2 A cross-site request forgery vulnerability in this package can allow an attacker to inject arbitrary values and forge malicious requests on behalf of a user. The attacker may inject arbitrary values without any authentication, or perform various malicious actions on behalf of an authenticated user, potentially compromising the security and integrity of the application. The vulnerability is caused by improper validation and enforcement of CSRF tokens within the application. For 'safe' methods, the token is extracted from the cookie and saved to storage without further validation or sanitization. In addition, the CSRF token is validated against tokens in storage but not associated with a session, nor by using a Double Submit Cookie Method, allowing for token reuse. Fixed in
2.50.0
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-41338
GO-2023-2052
GHSA-3q5p-3558-364f
Sep 12, 2023
IsFromLocal local address check can be circumvented in github.com/gofiber/fiber/v2 The Ctx.IsFromLocal function can incorrectly report a request as being sent from localhost when the request contains an X-Forwarded-For header containing a localhost IP address. Fixed in
2.49.2-0.20230906112033-b8c9ede6efa2
References Updated May 20, 2024 · Source: OSV.dev
CVE-2018-20744
GHSA-927h-x4qj-r242
GO-2023-1792
May 14, 2022
github.com/gofiber/fiber/v2 vulnerable to Origin Validation Error
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
The Olivier Poitrey Go CORS handler through 1.3.0 actively converts a wildcard CORS policy into reflecting an arbitrary Origin header value, which is incompatible with the CORS security design, and could lead to CORS misconfiguration security problems. Fixed in
2.43.0
References Updated May 20, 2024 · Source: OSV.dev |
v2.32.0
minor
Dependencies (2)
|
|
v2.26.0
minor
11 CVEs
CVE-2026-42554
GO-2026-5585
GHSA-qjv7-627w-8qjv
Jul 24, 2026
Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fixed in
2.52.13
Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-45045
GHSA-gcfq-8gqf-4876
GO-2026-5887
Jul 02, 2026
GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryThe Vulnerable CodeFile:
Data Flow
Impact
FixReplace
Fixed in
2.52.14
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25882
GO-2026-4543
GHSA-mrq8-rjmw-wpq3
Feb 26, 2026
Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fixed in
2.52.12
References Updated Feb 26, 2026 · Source: OSV.dev
CVE-2025-66630
GO-2026-4471
GHSA-68rr-p4fp-j59v
Feb 19, 2026
Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() on crypto/rand failure in github.com/gofiber/fiber Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() — predictable / zero‑UUID on crypto/rand failure in github.com/gofiber/fiber Fixed in
2.52.11
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-54801
GO-2025-3845
GHSA-qx2q-88mx-vhg7
Aug 11, 2025
Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fixed in
2.52.9
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-38513
GO-2024-2959
GHSA-98j2-3j3p-fw2v
Jul 02, 2024
Session Middleware Token Injection Vulnerability in github.com/gofiber/fiber Session Middleware Token Injection Vulnerability in github.com/gofiber/fiber Fixed in
2.52.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-25124
GO-2024-2574
GHSA-fmg4-x8pw-hjhg
May 20, 2024
Insecure CORS Configuration allowing wildcard origin with credentials in github.com/gofiber/fiber/v2 The CORS middleware allows for insecure configurations that could potentially expose the application to multiple CORS-related vulnerabilities. Specifically, it allows setting the Access-Control-Allow-Origin header to a wildcard ("*") while also having the Access-Control-Allow-Credentials set to true, which goes against recommended security best practices. Fixed in
2.52.1
References
Updated May 20, 2024 · Source: OSV.dev
CVE-2023-45141
GO-2023-2116
GHSA-mv73-f69x-444p
Oct 24, 2023
CSRF token validation vulnerability in github.com/gofiber/fiber/v2 A cross-site request forgery vulnerability can allow an attacker to obtain tokens and forge malicious requests on behalf of a user. This can lead to unauthorized actions being taken on the user's behalf, potentially compromising the security and integrity of the application. The vulnerability is caused by improper validation and enforcement of CSRF tokens within the application. The CSRF token is validated against tokens in storage but was is not tied to the original requestor that generated it, allowing for token reuse. Fixed in
2.50.0
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-45128
GO-2023-2115
GHSA-94w9-97p3-p368
Oct 24, 2023
CSRF token reuse vulnerability in github.com/gofiber/fiber/v2 A cross-site request forgery vulnerability in this package can allow an attacker to inject arbitrary values and forge malicious requests on behalf of a user. The attacker may inject arbitrary values without any authentication, or perform various malicious actions on behalf of an authenticated user, potentially compromising the security and integrity of the application. The vulnerability is caused by improper validation and enforcement of CSRF tokens within the application. For 'safe' methods, the token is extracted from the cookie and saved to storage without further validation or sanitization. In addition, the CSRF token is validated against tokens in storage but not associated with a session, nor by using a Double Submit Cookie Method, allowing for token reuse. Fixed in
2.50.0
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-41338
GO-2023-2052
GHSA-3q5p-3558-364f
Sep 12, 2023
IsFromLocal local address check can be circumvented in github.com/gofiber/fiber/v2 The Ctx.IsFromLocal function can incorrectly report a request as being sent from localhost when the request contains an X-Forwarded-For header containing a localhost IP address. Fixed in
2.49.2-0.20230906112033-b8c9ede6efa2
References Updated May 20, 2024 · Source: OSV.dev
CVE-2018-20744
GHSA-927h-x4qj-r242
GO-2023-1792
May 14, 2022
github.com/gofiber/fiber/v2 vulnerable to Origin Validation Error
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
The Olivier Poitrey Go CORS handler through 1.3.0 actively converts a wildcard CORS policy into reflecting an arbitrary Origin header value, which is incompatible with the CORS security design, and could lead to CORS misconfiguration security problems. Fixed in
2.43.0
References Updated May 20, 2024 · Source: OSV.dev |
v2.26.0
minor
Dependencies (2)
|
|
v2.23.0
minor
11 CVEs
CVE-2026-42554
GO-2026-5585
GHSA-qjv7-627w-8qjv
Jul 24, 2026
Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fixed in
2.52.13
Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-45045
GHSA-gcfq-8gqf-4876
GO-2026-5887
Jul 02, 2026
GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryThe Vulnerable CodeFile:
Data Flow
Impact
FixReplace
Fixed in
2.52.14
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25882
GO-2026-4543
GHSA-mrq8-rjmw-wpq3
Feb 26, 2026
Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fixed in
2.52.12
References Updated Feb 26, 2026 · Source: OSV.dev
CVE-2025-66630
GO-2026-4471
GHSA-68rr-p4fp-j59v
Feb 19, 2026
Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() on crypto/rand failure in github.com/gofiber/fiber Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() — predictable / zero‑UUID on crypto/rand failure in github.com/gofiber/fiber Fixed in
2.52.11
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-54801
GO-2025-3845
GHSA-qx2q-88mx-vhg7
Aug 11, 2025
Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fixed in
2.52.9
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-38513
GO-2024-2959
GHSA-98j2-3j3p-fw2v
Jul 02, 2024
Session Middleware Token Injection Vulnerability in github.com/gofiber/fiber Session Middleware Token Injection Vulnerability in github.com/gofiber/fiber Fixed in
2.52.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-25124
GO-2024-2574
GHSA-fmg4-x8pw-hjhg
May 20, 2024
Insecure CORS Configuration allowing wildcard origin with credentials in github.com/gofiber/fiber/v2 The CORS middleware allows for insecure configurations that could potentially expose the application to multiple CORS-related vulnerabilities. Specifically, it allows setting the Access-Control-Allow-Origin header to a wildcard ("*") while also having the Access-Control-Allow-Credentials set to true, which goes against recommended security best practices. Fixed in
2.52.1
References
Updated May 20, 2024 · Source: OSV.dev
CVE-2023-45141
GO-2023-2116
GHSA-mv73-f69x-444p
Oct 24, 2023
CSRF token validation vulnerability in github.com/gofiber/fiber/v2 A cross-site request forgery vulnerability can allow an attacker to obtain tokens and forge malicious requests on behalf of a user. This can lead to unauthorized actions being taken on the user's behalf, potentially compromising the security and integrity of the application. The vulnerability is caused by improper validation and enforcement of CSRF tokens within the application. The CSRF token is validated against tokens in storage but was is not tied to the original requestor that generated it, allowing for token reuse. Fixed in
2.50.0
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-45128
GO-2023-2115
GHSA-94w9-97p3-p368
Oct 24, 2023
CSRF token reuse vulnerability in github.com/gofiber/fiber/v2 A cross-site request forgery vulnerability in this package can allow an attacker to inject arbitrary values and forge malicious requests on behalf of a user. The attacker may inject arbitrary values without any authentication, or perform various malicious actions on behalf of an authenticated user, potentially compromising the security and integrity of the application. The vulnerability is caused by improper validation and enforcement of CSRF tokens within the application. For 'safe' methods, the token is extracted from the cookie and saved to storage without further validation or sanitization. In addition, the CSRF token is validated against tokens in storage but not associated with a session, nor by using a Double Submit Cookie Method, allowing for token reuse. Fixed in
2.50.0
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-41338
GO-2023-2052
GHSA-3q5p-3558-364f
Sep 12, 2023
IsFromLocal local address check can be circumvented in github.com/gofiber/fiber/v2 The Ctx.IsFromLocal function can incorrectly report a request as being sent from localhost when the request contains an X-Forwarded-For header containing a localhost IP address. Fixed in
2.49.2-0.20230906112033-b8c9ede6efa2
References Updated May 20, 2024 · Source: OSV.dev
CVE-2018-20744
GHSA-927h-x4qj-r242
GO-2023-1792
May 14, 2022
github.com/gofiber/fiber/v2 vulnerable to Origin Validation Error
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
The Olivier Poitrey Go CORS handler through 1.3.0 actively converts a wildcard CORS policy into reflecting an arbitrary Origin header value, which is incompatible with the CORS security design, and could lead to CORS misconfiguration security problems. Fixed in
2.43.0
References Updated May 20, 2024 · Source: OSV.dev |
v2.23.0
minor
Dependencies (2)
|
|
v2.21.0
minor
11 CVEs
CVE-2026-42554
GO-2026-5585
GHSA-qjv7-627w-8qjv
Jul 24, 2026
Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fixed in
2.52.13
Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-45045
GHSA-gcfq-8gqf-4876
GO-2026-5887
Jul 02, 2026
GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryThe Vulnerable CodeFile:
Data Flow
Impact
FixReplace
Fixed in
2.52.14
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25882
GO-2026-4543
GHSA-mrq8-rjmw-wpq3
Feb 26, 2026
Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fixed in
2.52.12
References Updated Feb 26, 2026 · Source: OSV.dev
CVE-2025-66630
GO-2026-4471
GHSA-68rr-p4fp-j59v
Feb 19, 2026
Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() on crypto/rand failure in github.com/gofiber/fiber Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() — predictable / zero‑UUID on crypto/rand failure in github.com/gofiber/fiber Fixed in
2.52.11
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-54801
GO-2025-3845
GHSA-qx2q-88mx-vhg7
Aug 11, 2025
Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fixed in
2.52.9
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-38513
GO-2024-2959
GHSA-98j2-3j3p-fw2v
Jul 02, 2024
Session Middleware Token Injection Vulnerability in github.com/gofiber/fiber Session Middleware Token Injection Vulnerability in github.com/gofiber/fiber Fixed in
2.52.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-25124
GO-2024-2574
GHSA-fmg4-x8pw-hjhg
May 20, 2024
Insecure CORS Configuration allowing wildcard origin with credentials in github.com/gofiber/fiber/v2 The CORS middleware allows for insecure configurations that could potentially expose the application to multiple CORS-related vulnerabilities. Specifically, it allows setting the Access-Control-Allow-Origin header to a wildcard ("*") while also having the Access-Control-Allow-Credentials set to true, which goes against recommended security best practices. Fixed in
2.52.1
References
Updated May 20, 2024 · Source: OSV.dev
CVE-2023-45141
GO-2023-2116
GHSA-mv73-f69x-444p
Oct 24, 2023
CSRF token validation vulnerability in github.com/gofiber/fiber/v2 A cross-site request forgery vulnerability can allow an attacker to obtain tokens and forge malicious requests on behalf of a user. This can lead to unauthorized actions being taken on the user's behalf, potentially compromising the security and integrity of the application. The vulnerability is caused by improper validation and enforcement of CSRF tokens within the application. The CSRF token is validated against tokens in storage but was is not tied to the original requestor that generated it, allowing for token reuse. Fixed in
2.50.0
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-45128
GO-2023-2115
GHSA-94w9-97p3-p368
Oct 24, 2023
CSRF token reuse vulnerability in github.com/gofiber/fiber/v2 A cross-site request forgery vulnerability in this package can allow an attacker to inject arbitrary values and forge malicious requests on behalf of a user. The attacker may inject arbitrary values without any authentication, or perform various malicious actions on behalf of an authenticated user, potentially compromising the security and integrity of the application. The vulnerability is caused by improper validation and enforcement of CSRF tokens within the application. For 'safe' methods, the token is extracted from the cookie and saved to storage without further validation or sanitization. In addition, the CSRF token is validated against tokens in storage but not associated with a session, nor by using a Double Submit Cookie Method, allowing for token reuse. Fixed in
2.50.0
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-41338
GO-2023-2052
GHSA-3q5p-3558-364f
Sep 12, 2023
IsFromLocal local address check can be circumvented in github.com/gofiber/fiber/v2 The Ctx.IsFromLocal function can incorrectly report a request as being sent from localhost when the request contains an X-Forwarded-For header containing a localhost IP address. Fixed in
2.49.2-0.20230906112033-b8c9ede6efa2
References Updated May 20, 2024 · Source: OSV.dev
CVE-2018-20744
GHSA-927h-x4qj-r242
GO-2023-1792
May 14, 2022
github.com/gofiber/fiber/v2 vulnerable to Origin Validation Error
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
The Olivier Poitrey Go CORS handler through 1.3.0 actively converts a wildcard CORS policy into reflecting an arbitrary Origin header value, which is incompatible with the CORS security design, and could lead to CORS misconfiguration security problems. Fixed in
2.43.0
References Updated May 20, 2024 · Source: OSV.dev |
v2.21.0
minor
Dependencies (2)
|
|
v2.20.1
patch
11 CVEs
CVE-2026-42554
GO-2026-5585
GHSA-qjv7-627w-8qjv
Jul 24, 2026
Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fixed in
2.52.13
Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-45045
GHSA-gcfq-8gqf-4876
GO-2026-5887
Jul 02, 2026
GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryThe Vulnerable CodeFile:
Data Flow
Impact
FixReplace
Fixed in
2.52.14
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25882
GO-2026-4543
GHSA-mrq8-rjmw-wpq3
Feb 26, 2026
Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fixed in
2.52.12
References Updated Feb 26, 2026 · Source: OSV.dev
CVE-2025-66630
GO-2026-4471
GHSA-68rr-p4fp-j59v
Feb 19, 2026
Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() on crypto/rand failure in github.com/gofiber/fiber Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() — predictable / zero‑UUID on crypto/rand failure in github.com/gofiber/fiber Fixed in
2.52.11
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-54801
GO-2025-3845
GHSA-qx2q-88mx-vhg7
Aug 11, 2025
Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fixed in
2.52.9
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-38513
GO-2024-2959
GHSA-98j2-3j3p-fw2v
Jul 02, 2024
Session Middleware Token Injection Vulnerability in github.com/gofiber/fiber Session Middleware Token Injection Vulnerability in github.com/gofiber/fiber Fixed in
2.52.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-25124
GO-2024-2574
GHSA-fmg4-x8pw-hjhg
May 20, 2024
Insecure CORS Configuration allowing wildcard origin with credentials in github.com/gofiber/fiber/v2 The CORS middleware allows for insecure configurations that could potentially expose the application to multiple CORS-related vulnerabilities. Specifically, it allows setting the Access-Control-Allow-Origin header to a wildcard ("*") while also having the Access-Control-Allow-Credentials set to true, which goes against recommended security best practices. Fixed in
2.52.1
References
Updated May 20, 2024 · Source: OSV.dev
CVE-2023-45141
GO-2023-2116
GHSA-mv73-f69x-444p
Oct 24, 2023
CSRF token validation vulnerability in github.com/gofiber/fiber/v2 A cross-site request forgery vulnerability can allow an attacker to obtain tokens and forge malicious requests on behalf of a user. This can lead to unauthorized actions being taken on the user's behalf, potentially compromising the security and integrity of the application. The vulnerability is caused by improper validation and enforcement of CSRF tokens within the application. The CSRF token is validated against tokens in storage but was is not tied to the original requestor that generated it, allowing for token reuse. Fixed in
2.50.0
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-45128
GO-2023-2115
GHSA-94w9-97p3-p368
Oct 24, 2023
CSRF token reuse vulnerability in github.com/gofiber/fiber/v2 A cross-site request forgery vulnerability in this package can allow an attacker to inject arbitrary values and forge malicious requests on behalf of a user. The attacker may inject arbitrary values without any authentication, or perform various malicious actions on behalf of an authenticated user, potentially compromising the security and integrity of the application. The vulnerability is caused by improper validation and enforcement of CSRF tokens within the application. For 'safe' methods, the token is extracted from the cookie and saved to storage without further validation or sanitization. In addition, the CSRF token is validated against tokens in storage but not associated with a session, nor by using a Double Submit Cookie Method, allowing for token reuse. Fixed in
2.50.0
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-41338
GO-2023-2052
GHSA-3q5p-3558-364f
Sep 12, 2023
IsFromLocal local address check can be circumvented in github.com/gofiber/fiber/v2 The Ctx.IsFromLocal function can incorrectly report a request as being sent from localhost when the request contains an X-Forwarded-For header containing a localhost IP address. Fixed in
2.49.2-0.20230906112033-b8c9ede6efa2
References Updated May 20, 2024 · Source: OSV.dev
CVE-2018-20744
GHSA-927h-x4qj-r242
GO-2023-1792
May 14, 2022
github.com/gofiber/fiber/v2 vulnerable to Origin Validation Error
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
The Olivier Poitrey Go CORS handler through 1.3.0 actively converts a wildcard CORS policy into reflecting an arbitrary Origin header value, which is incompatible with the CORS security design, and could lead to CORS misconfiguration security problems. Fixed in
2.43.0
References Updated May 20, 2024 · Source: OSV.dev |
v2.20.1
patch
Dependencies (2)
|
|
v2.20.0
minor
11 CVEs
CVE-2026-42554
GO-2026-5585
GHSA-qjv7-627w-8qjv
Jul 24, 2026
Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fixed in
2.52.13
Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-45045
GHSA-gcfq-8gqf-4876
GO-2026-5887
Jul 02, 2026
GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryThe Vulnerable CodeFile:
Data Flow
Impact
FixReplace
Fixed in
2.52.14
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25882
GO-2026-4543
GHSA-mrq8-rjmw-wpq3
Feb 26, 2026
Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fixed in
2.52.12
References Updated Feb 26, 2026 · Source: OSV.dev
CVE-2025-66630
GO-2026-4471
GHSA-68rr-p4fp-j59v
Feb 19, 2026
Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() on crypto/rand failure in github.com/gofiber/fiber Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() — predictable / zero‑UUID on crypto/rand failure in github.com/gofiber/fiber Fixed in
2.52.11
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-54801
GO-2025-3845
GHSA-qx2q-88mx-vhg7
Aug 11, 2025
Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fixed in
2.52.9
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-38513
GO-2024-2959
GHSA-98j2-3j3p-fw2v
Jul 02, 2024
Session Middleware Token Injection Vulnerability in github.com/gofiber/fiber Session Middleware Token Injection Vulnerability in github.com/gofiber/fiber Fixed in
2.52.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-25124
GO-2024-2574
GHSA-fmg4-x8pw-hjhg
May 20, 2024
Insecure CORS Configuration allowing wildcard origin with credentials in github.com/gofiber/fiber/v2 The CORS middleware allows for insecure configurations that could potentially expose the application to multiple CORS-related vulnerabilities. Specifically, it allows setting the Access-Control-Allow-Origin header to a wildcard ("*") while also having the Access-Control-Allow-Credentials set to true, which goes against recommended security best practices. Fixed in
2.52.1
References
Updated May 20, 2024 · Source: OSV.dev
CVE-2023-45141
GO-2023-2116
GHSA-mv73-f69x-444p
Oct 24, 2023
CSRF token validation vulnerability in github.com/gofiber/fiber/v2 A cross-site request forgery vulnerability can allow an attacker to obtain tokens and forge malicious requests on behalf of a user. This can lead to unauthorized actions being taken on the user's behalf, potentially compromising the security and integrity of the application. The vulnerability is caused by improper validation and enforcement of CSRF tokens within the application. The CSRF token is validated against tokens in storage but was is not tied to the original requestor that generated it, allowing for token reuse. Fixed in
2.50.0
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-45128
GO-2023-2115
GHSA-94w9-97p3-p368
Oct 24, 2023
CSRF token reuse vulnerability in github.com/gofiber/fiber/v2 A cross-site request forgery vulnerability in this package can allow an attacker to inject arbitrary values and forge malicious requests on behalf of a user. The attacker may inject arbitrary values without any authentication, or perform various malicious actions on behalf of an authenticated user, potentially compromising the security and integrity of the application. The vulnerability is caused by improper validation and enforcement of CSRF tokens within the application. For 'safe' methods, the token is extracted from the cookie and saved to storage without further validation or sanitization. In addition, the CSRF token is validated against tokens in storage but not associated with a session, nor by using a Double Submit Cookie Method, allowing for token reuse. Fixed in
2.50.0
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-41338
GO-2023-2052
GHSA-3q5p-3558-364f
Sep 12, 2023
IsFromLocal local address check can be circumvented in github.com/gofiber/fiber/v2 The Ctx.IsFromLocal function can incorrectly report a request as being sent from localhost when the request contains an X-Forwarded-For header containing a localhost IP address. Fixed in
2.49.2-0.20230906112033-b8c9ede6efa2
References Updated May 20, 2024 · Source: OSV.dev
CVE-2018-20744
GHSA-927h-x4qj-r242
GO-2023-1792
May 14, 2022
github.com/gofiber/fiber/v2 vulnerable to Origin Validation Error
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
The Olivier Poitrey Go CORS handler through 1.3.0 actively converts a wildcard CORS policy into reflecting an arbitrary Origin header value, which is incompatible with the CORS security design, and could lead to CORS misconfiguration security problems. Fixed in
2.43.0
References Updated May 20, 2024 · Source: OSV.dev |
v2.20.0
minor
Dependencies (2)
|
|
v2.18.0
minor
11 CVEs
CVE-2026-42554
GO-2026-5585
GHSA-qjv7-627w-8qjv
Jul 24, 2026
Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fixed in
2.52.13
Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-45045
GHSA-gcfq-8gqf-4876
GO-2026-5887
Jul 02, 2026
GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryThe Vulnerable CodeFile:
Data Flow
Impact
FixReplace
Fixed in
2.52.14
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25882
GO-2026-4543
GHSA-mrq8-rjmw-wpq3
Feb 26, 2026
Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fixed in
2.52.12
References Updated Feb 26, 2026 · Source: OSV.dev
CVE-2025-66630
GO-2026-4471
GHSA-68rr-p4fp-j59v
Feb 19, 2026
Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() on crypto/rand failure in github.com/gofiber/fiber Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() — predictable / zero‑UUID on crypto/rand failure in github.com/gofiber/fiber Fixed in
2.52.11
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-54801
GO-2025-3845
GHSA-qx2q-88mx-vhg7
Aug 11, 2025
Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fixed in
2.52.9
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-38513
GO-2024-2959
GHSA-98j2-3j3p-fw2v
Jul 02, 2024
Session Middleware Token Injection Vulnerability in github.com/gofiber/fiber Session Middleware Token Injection Vulnerability in github.com/gofiber/fiber Fixed in
2.52.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-25124
GO-2024-2574
GHSA-fmg4-x8pw-hjhg
May 20, 2024
Insecure CORS Configuration allowing wildcard origin with credentials in github.com/gofiber/fiber/v2 The CORS middleware allows for insecure configurations that could potentially expose the application to multiple CORS-related vulnerabilities. Specifically, it allows setting the Access-Control-Allow-Origin header to a wildcard ("*") while also having the Access-Control-Allow-Credentials set to true, which goes against recommended security best practices. Fixed in
2.52.1
References
Updated May 20, 2024 · Source: OSV.dev
CVE-2023-45141
GO-2023-2116
GHSA-mv73-f69x-444p
Oct 24, 2023
CSRF token validation vulnerability in github.com/gofiber/fiber/v2 A cross-site request forgery vulnerability can allow an attacker to obtain tokens and forge malicious requests on behalf of a user. This can lead to unauthorized actions being taken on the user's behalf, potentially compromising the security and integrity of the application. The vulnerability is caused by improper validation and enforcement of CSRF tokens within the application. The CSRF token is validated against tokens in storage but was is not tied to the original requestor that generated it, allowing for token reuse. Fixed in
2.50.0
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-45128
GO-2023-2115
GHSA-94w9-97p3-p368
Oct 24, 2023
CSRF token reuse vulnerability in github.com/gofiber/fiber/v2 A cross-site request forgery vulnerability in this package can allow an attacker to inject arbitrary values and forge malicious requests on behalf of a user. The attacker may inject arbitrary values without any authentication, or perform various malicious actions on behalf of an authenticated user, potentially compromising the security and integrity of the application. The vulnerability is caused by improper validation and enforcement of CSRF tokens within the application. For 'safe' methods, the token is extracted from the cookie and saved to storage without further validation or sanitization. In addition, the CSRF token is validated against tokens in storage but not associated with a session, nor by using a Double Submit Cookie Method, allowing for token reuse. Fixed in
2.50.0
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-41338
GO-2023-2052
GHSA-3q5p-3558-364f
Sep 12, 2023
IsFromLocal local address check can be circumvented in github.com/gofiber/fiber/v2 The Ctx.IsFromLocal function can incorrectly report a request as being sent from localhost when the request contains an X-Forwarded-For header containing a localhost IP address. Fixed in
2.49.2-0.20230906112033-b8c9ede6efa2
References Updated May 20, 2024 · Source: OSV.dev
CVE-2018-20744
GHSA-927h-x4qj-r242
GO-2023-1792
May 14, 2022
github.com/gofiber/fiber/v2 vulnerable to Origin Validation Error
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
The Olivier Poitrey Go CORS handler through 1.3.0 actively converts a wildcard CORS policy into reflecting an arbitrary Origin header value, which is incompatible with the CORS security design, and could lead to CORS misconfiguration security problems. Fixed in
2.43.0
References Updated May 20, 2024 · Source: OSV.dev |
v2.18.0
minor
Dependencies (2)
|
|
v2.17.0
minor
11 CVEs
CVE-2026-42554
GO-2026-5585
GHSA-qjv7-627w-8qjv
Jul 24, 2026
Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fixed in
2.52.13
Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-45045
GHSA-gcfq-8gqf-4876
GO-2026-5887
Jul 02, 2026
GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryThe Vulnerable CodeFile:
Data Flow
Impact
FixReplace
Fixed in
2.52.14
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25882
GO-2026-4543
GHSA-mrq8-rjmw-wpq3
Feb 26, 2026
Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fixed in
2.52.12
References Updated Feb 26, 2026 · Source: OSV.dev
CVE-2025-66630
GO-2026-4471
GHSA-68rr-p4fp-j59v
Feb 19, 2026
Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() on crypto/rand failure in github.com/gofiber/fiber Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() — predictable / zero‑UUID on crypto/rand failure in github.com/gofiber/fiber Fixed in
2.52.11
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-54801
GO-2025-3845
GHSA-qx2q-88mx-vhg7
Aug 11, 2025
Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fixed in
2.52.9
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-38513
GO-2024-2959
GHSA-98j2-3j3p-fw2v
Jul 02, 2024
Session Middleware Token Injection Vulnerability in github.com/gofiber/fiber Session Middleware Token Injection Vulnerability in github.com/gofiber/fiber Fixed in
2.52.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-25124
GO-2024-2574
GHSA-fmg4-x8pw-hjhg
May 20, 2024
Insecure CORS Configuration allowing wildcard origin with credentials in github.com/gofiber/fiber/v2 The CORS middleware allows for insecure configurations that could potentially expose the application to multiple CORS-related vulnerabilities. Specifically, it allows setting the Access-Control-Allow-Origin header to a wildcard ("*") while also having the Access-Control-Allow-Credentials set to true, which goes against recommended security best practices. Fixed in
2.52.1
References
Updated May 20, 2024 · Source: OSV.dev
CVE-2023-45141
GO-2023-2116
GHSA-mv73-f69x-444p
Oct 24, 2023
CSRF token validation vulnerability in github.com/gofiber/fiber/v2 A cross-site request forgery vulnerability can allow an attacker to obtain tokens and forge malicious requests on behalf of a user. This can lead to unauthorized actions being taken on the user's behalf, potentially compromising the security and integrity of the application. The vulnerability is caused by improper validation and enforcement of CSRF tokens within the application. The CSRF token is validated against tokens in storage but was is not tied to the original requestor that generated it, allowing for token reuse. Fixed in
2.50.0
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-45128
GO-2023-2115
GHSA-94w9-97p3-p368
Oct 24, 2023
CSRF token reuse vulnerability in github.com/gofiber/fiber/v2 A cross-site request forgery vulnerability in this package can allow an attacker to inject arbitrary values and forge malicious requests on behalf of a user. The attacker may inject arbitrary values without any authentication, or perform various malicious actions on behalf of an authenticated user, potentially compromising the security and integrity of the application. The vulnerability is caused by improper validation and enforcement of CSRF tokens within the application. For 'safe' methods, the token is extracted from the cookie and saved to storage without further validation or sanitization. In addition, the CSRF token is validated against tokens in storage but not associated with a session, nor by using a Double Submit Cookie Method, allowing for token reuse. Fixed in
2.50.0
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-41338
GO-2023-2052
GHSA-3q5p-3558-364f
Sep 12, 2023
IsFromLocal local address check can be circumvented in github.com/gofiber/fiber/v2 The Ctx.IsFromLocal function can incorrectly report a request as being sent from localhost when the request contains an X-Forwarded-For header containing a localhost IP address. Fixed in
2.49.2-0.20230906112033-b8c9ede6efa2
References Updated May 20, 2024 · Source: OSV.dev
CVE-2018-20744
GHSA-927h-x4qj-r242
GO-2023-1792
May 14, 2022
github.com/gofiber/fiber/v2 vulnerable to Origin Validation Error
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
The Olivier Poitrey Go CORS handler through 1.3.0 actively converts a wildcard CORS policy into reflecting an arbitrary Origin header value, which is incompatible with the CORS security design, and could lead to CORS misconfiguration security problems. Fixed in
2.43.0
References Updated May 20, 2024 · Source: OSV.dev |
v2.17.0
minor
Dependencies (2)
|
|
v2.16.0
minor
11 CVEs
CVE-2026-42554
GO-2026-5585
GHSA-qjv7-627w-8qjv
Jul 24, 2026
Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fixed in
2.52.13
Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-45045
GHSA-gcfq-8gqf-4876
GO-2026-5887
Jul 02, 2026
GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryThe Vulnerable CodeFile:
Data Flow
Impact
FixReplace
Fixed in
2.52.14
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25882
GO-2026-4543
GHSA-mrq8-rjmw-wpq3
Feb 26, 2026
Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fixed in
2.52.12
References Updated Feb 26, 2026 · Source: OSV.dev
CVE-2025-66630
GO-2026-4471
GHSA-68rr-p4fp-j59v
Feb 19, 2026
Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() on crypto/rand failure in github.com/gofiber/fiber Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() — predictable / zero‑UUID on crypto/rand failure in github.com/gofiber/fiber Fixed in
2.52.11
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-54801
GO-2025-3845
GHSA-qx2q-88mx-vhg7
Aug 11, 2025
Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fixed in
2.52.9
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-38513
GO-2024-2959
GHSA-98j2-3j3p-fw2v
Jul 02, 2024
Session Middleware Token Injection Vulnerability in github.com/gofiber/fiber Session Middleware Token Injection Vulnerability in github.com/gofiber/fiber Fixed in
2.52.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-25124
GO-2024-2574
GHSA-fmg4-x8pw-hjhg
May 20, 2024
Insecure CORS Configuration allowing wildcard origin with credentials in github.com/gofiber/fiber/v2 The CORS middleware allows for insecure configurations that could potentially expose the application to multiple CORS-related vulnerabilities. Specifically, it allows setting the Access-Control-Allow-Origin header to a wildcard ("*") while also having the Access-Control-Allow-Credentials set to true, which goes against recommended security best practices. Fixed in
2.52.1
References
Updated May 20, 2024 · Source: OSV.dev
CVE-2023-45141
GO-2023-2116
GHSA-mv73-f69x-444p
Oct 24, 2023
CSRF token validation vulnerability in github.com/gofiber/fiber/v2 A cross-site request forgery vulnerability can allow an attacker to obtain tokens and forge malicious requests on behalf of a user. This can lead to unauthorized actions being taken on the user's behalf, potentially compromising the security and integrity of the application. The vulnerability is caused by improper validation and enforcement of CSRF tokens within the application. The CSRF token is validated against tokens in storage but was is not tied to the original requestor that generated it, allowing for token reuse. Fixed in
2.50.0
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-45128
GO-2023-2115
GHSA-94w9-97p3-p368
Oct 24, 2023
CSRF token reuse vulnerability in github.com/gofiber/fiber/v2 A cross-site request forgery vulnerability in this package can allow an attacker to inject arbitrary values and forge malicious requests on behalf of a user. The attacker may inject arbitrary values without any authentication, or perform various malicious actions on behalf of an authenticated user, potentially compromising the security and integrity of the application. The vulnerability is caused by improper validation and enforcement of CSRF tokens within the application. For 'safe' methods, the token is extracted from the cookie and saved to storage without further validation or sanitization. In addition, the CSRF token is validated against tokens in storage but not associated with a session, nor by using a Double Submit Cookie Method, allowing for token reuse. Fixed in
2.50.0
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-41338
GO-2023-2052
GHSA-3q5p-3558-364f
Sep 12, 2023
IsFromLocal local address check can be circumvented in github.com/gofiber/fiber/v2 The Ctx.IsFromLocal function can incorrectly report a request as being sent from localhost when the request contains an X-Forwarded-For header containing a localhost IP address. Fixed in
2.49.2-0.20230906112033-b8c9ede6efa2
References Updated May 20, 2024 · Source: OSV.dev
CVE-2018-20744
GHSA-927h-x4qj-r242
GO-2023-1792
May 14, 2022
github.com/gofiber/fiber/v2 vulnerable to Origin Validation Error
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
The Olivier Poitrey Go CORS handler through 1.3.0 actively converts a wildcard CORS policy into reflecting an arbitrary Origin header value, which is incompatible with the CORS security design, and could lead to CORS misconfiguration security problems. Fixed in
2.43.0
References Updated May 20, 2024 · Source: OSV.dev |
v2.16.0
minor
Dependencies (2)
|
|
v2.15.0
minor
11 CVEs
CVE-2026-42554
GO-2026-5585
GHSA-qjv7-627w-8qjv
Jul 24, 2026
Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fixed in
2.52.13
Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-45045
GHSA-gcfq-8gqf-4876
GO-2026-5887
Jul 02, 2026
GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryThe Vulnerable CodeFile:
Data Flow
Impact
FixReplace
Fixed in
2.52.14
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25882
GO-2026-4543
GHSA-mrq8-rjmw-wpq3
Feb 26, 2026
Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fixed in
2.52.12
References Updated Feb 26, 2026 · Source: OSV.dev
CVE-2025-66630
GO-2026-4471
GHSA-68rr-p4fp-j59v
Feb 19, 2026
Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() on crypto/rand failure in github.com/gofiber/fiber Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() — predictable / zero‑UUID on crypto/rand failure in github.com/gofiber/fiber Fixed in
2.52.11
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-54801
GO-2025-3845
GHSA-qx2q-88mx-vhg7
Aug 11, 2025
Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fixed in
2.52.9
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-38513
GO-2024-2959
GHSA-98j2-3j3p-fw2v
Jul 02, 2024
Session Middleware Token Injection Vulnerability in github.com/gofiber/fiber Session Middleware Token Injection Vulnerability in github.com/gofiber/fiber Fixed in
2.52.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-25124
GO-2024-2574
GHSA-fmg4-x8pw-hjhg
May 20, 2024
Insecure CORS Configuration allowing wildcard origin with credentials in github.com/gofiber/fiber/v2 The CORS middleware allows for insecure configurations that could potentially expose the application to multiple CORS-related vulnerabilities. Specifically, it allows setting the Access-Control-Allow-Origin header to a wildcard ("*") while also having the Access-Control-Allow-Credentials set to true, which goes against recommended security best practices. Fixed in
2.52.1
References
Updated May 20, 2024 · Source: OSV.dev
CVE-2023-45141
GO-2023-2116
GHSA-mv73-f69x-444p
Oct 24, 2023
CSRF token validation vulnerability in github.com/gofiber/fiber/v2 A cross-site request forgery vulnerability can allow an attacker to obtain tokens and forge malicious requests on behalf of a user. This can lead to unauthorized actions being taken on the user's behalf, potentially compromising the security and integrity of the application. The vulnerability is caused by improper validation and enforcement of CSRF tokens within the application. The CSRF token is validated against tokens in storage but was is not tied to the original requestor that generated it, allowing for token reuse. Fixed in
2.50.0
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-45128
GO-2023-2115
GHSA-94w9-97p3-p368
Oct 24, 2023
CSRF token reuse vulnerability in github.com/gofiber/fiber/v2 A cross-site request forgery vulnerability in this package can allow an attacker to inject arbitrary values and forge malicious requests on behalf of a user. The attacker may inject arbitrary values without any authentication, or perform various malicious actions on behalf of an authenticated user, potentially compromising the security and integrity of the application. The vulnerability is caused by improper validation and enforcement of CSRF tokens within the application. For 'safe' methods, the token is extracted from the cookie and saved to storage without further validation or sanitization. In addition, the CSRF token is validated against tokens in storage but not associated with a session, nor by using a Double Submit Cookie Method, allowing for token reuse. Fixed in
2.50.0
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-41338
GO-2023-2052
GHSA-3q5p-3558-364f
Sep 12, 2023
IsFromLocal local address check can be circumvented in github.com/gofiber/fiber/v2 The Ctx.IsFromLocal function can incorrectly report a request as being sent from localhost when the request contains an X-Forwarded-For header containing a localhost IP address. Fixed in
2.49.2-0.20230906112033-b8c9ede6efa2
References Updated May 20, 2024 · Source: OSV.dev
CVE-2018-20744
GHSA-927h-x4qj-r242
GO-2023-1792
May 14, 2022
github.com/gofiber/fiber/v2 vulnerable to Origin Validation Error
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
The Olivier Poitrey Go CORS handler through 1.3.0 actively converts a wildcard CORS policy into reflecting an arbitrary Origin header value, which is incompatible with the CORS security design, and could lead to CORS misconfiguration security problems. Fixed in
2.43.0
References Updated May 20, 2024 · Source: OSV.dev |
v2.15.0
minor
Dependencies (2)
|
|
v2.12.0
minor
11 CVEs
CVE-2026-42554
GO-2026-5585
GHSA-qjv7-627w-8qjv
Jul 24, 2026
Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fixed in
2.52.13
Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-45045
GHSA-gcfq-8gqf-4876
GO-2026-5887
Jul 02, 2026
GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryThe Vulnerable CodeFile:
Data Flow
Impact
FixReplace
Fixed in
2.52.14
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25882
GO-2026-4543
GHSA-mrq8-rjmw-wpq3
Feb 26, 2026
Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fixed in
2.52.12
References Updated Feb 26, 2026 · Source: OSV.dev
CVE-2025-66630
GO-2026-4471
GHSA-68rr-p4fp-j59v
Feb 19, 2026
Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() on crypto/rand failure in github.com/gofiber/fiber Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() — predictable / zero‑UUID on crypto/rand failure in github.com/gofiber/fiber Fixed in
2.52.11
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-54801
GO-2025-3845
GHSA-qx2q-88mx-vhg7
Aug 11, 2025
Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fixed in
2.52.9
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-38513
GO-2024-2959
GHSA-98j2-3j3p-fw2v
Jul 02, 2024
Session Middleware Token Injection Vulnerability in github.com/gofiber/fiber Session Middleware Token Injection Vulnerability in github.com/gofiber/fiber Fixed in
2.52.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-25124
GO-2024-2574
GHSA-fmg4-x8pw-hjhg
May 20, 2024
Insecure CORS Configuration allowing wildcard origin with credentials in github.com/gofiber/fiber/v2 The CORS middleware allows for insecure configurations that could potentially expose the application to multiple CORS-related vulnerabilities. Specifically, it allows setting the Access-Control-Allow-Origin header to a wildcard ("*") while also having the Access-Control-Allow-Credentials set to true, which goes against recommended security best practices. Fixed in
2.52.1
References
Updated May 20, 2024 · Source: OSV.dev
CVE-2023-45141
GO-2023-2116
GHSA-mv73-f69x-444p
Oct 24, 2023
CSRF token validation vulnerability in github.com/gofiber/fiber/v2 A cross-site request forgery vulnerability can allow an attacker to obtain tokens and forge malicious requests on behalf of a user. This can lead to unauthorized actions being taken on the user's behalf, potentially compromising the security and integrity of the application. The vulnerability is caused by improper validation and enforcement of CSRF tokens within the application. The CSRF token is validated against tokens in storage but was is not tied to the original requestor that generated it, allowing for token reuse. Fixed in
2.50.0
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-45128
GO-2023-2115
GHSA-94w9-97p3-p368
Oct 24, 2023
CSRF token reuse vulnerability in github.com/gofiber/fiber/v2 A cross-site request forgery vulnerability in this package can allow an attacker to inject arbitrary values and forge malicious requests on behalf of a user. The attacker may inject arbitrary values without any authentication, or perform various malicious actions on behalf of an authenticated user, potentially compromising the security and integrity of the application. The vulnerability is caused by improper validation and enforcement of CSRF tokens within the application. For 'safe' methods, the token is extracted from the cookie and saved to storage without further validation or sanitization. In addition, the CSRF token is validated against tokens in storage but not associated with a session, nor by using a Double Submit Cookie Method, allowing for token reuse. Fixed in
2.50.0
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-41338
GO-2023-2052
GHSA-3q5p-3558-364f
Sep 12, 2023
IsFromLocal local address check can be circumvented in github.com/gofiber/fiber/v2 The Ctx.IsFromLocal function can incorrectly report a request as being sent from localhost when the request contains an X-Forwarded-For header containing a localhost IP address. Fixed in
2.49.2-0.20230906112033-b8c9ede6efa2
References Updated May 20, 2024 · Source: OSV.dev
CVE-2018-20744
GHSA-927h-x4qj-r242
GO-2023-1792
May 14, 2022
github.com/gofiber/fiber/v2 vulnerable to Origin Validation Error
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
The Olivier Poitrey Go CORS handler through 1.3.0 actively converts a wildcard CORS policy into reflecting an arbitrary Origin header value, which is incompatible with the CORS security design, and could lead to CORS misconfiguration security problems. Fixed in
2.43.0
References Updated May 20, 2024 · Source: OSV.dev |
v2.12.0
minor
Dependencies (2)
|
|
v2.11.0
minor
11 CVEs
CVE-2026-42554
GO-2026-5585
GHSA-qjv7-627w-8qjv
Jul 24, 2026
Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fixed in
2.52.13
Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-45045
GHSA-gcfq-8gqf-4876
GO-2026-5887
Jul 02, 2026
GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryThe Vulnerable CodeFile:
Data Flow
Impact
FixReplace
Fixed in
2.52.14
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25882
GO-2026-4543
GHSA-mrq8-rjmw-wpq3
Feb 26, 2026
Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fixed in
2.52.12
References Updated Feb 26, 2026 · Source: OSV.dev
CVE-2025-66630
GO-2026-4471
GHSA-68rr-p4fp-j59v
Feb 19, 2026
Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() on crypto/rand failure in github.com/gofiber/fiber Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() — predictable / zero‑UUID on crypto/rand failure in github.com/gofiber/fiber Fixed in
2.52.11
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-54801
GO-2025-3845
GHSA-qx2q-88mx-vhg7
Aug 11, 2025
Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fixed in
2.52.9
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-38513
GO-2024-2959
GHSA-98j2-3j3p-fw2v
Jul 02, 2024
Session Middleware Token Injection Vulnerability in github.com/gofiber/fiber Session Middleware Token Injection Vulnerability in github.com/gofiber/fiber Fixed in
2.52.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-25124
GO-2024-2574
GHSA-fmg4-x8pw-hjhg
May 20, 2024
Insecure CORS Configuration allowing wildcard origin with credentials in github.com/gofiber/fiber/v2 The CORS middleware allows for insecure configurations that could potentially expose the application to multiple CORS-related vulnerabilities. Specifically, it allows setting the Access-Control-Allow-Origin header to a wildcard ("*") while also having the Access-Control-Allow-Credentials set to true, which goes against recommended security best practices. Fixed in
2.52.1
References
Updated May 20, 2024 · Source: OSV.dev
CVE-2023-45141
GO-2023-2116
GHSA-mv73-f69x-444p
Oct 24, 2023
CSRF token validation vulnerability in github.com/gofiber/fiber/v2 A cross-site request forgery vulnerability can allow an attacker to obtain tokens and forge malicious requests on behalf of a user. This can lead to unauthorized actions being taken on the user's behalf, potentially compromising the security and integrity of the application. The vulnerability is caused by improper validation and enforcement of CSRF tokens within the application. The CSRF token is validated against tokens in storage but was is not tied to the original requestor that generated it, allowing for token reuse. Fixed in
2.50.0
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-45128
GO-2023-2115
GHSA-94w9-97p3-p368
Oct 24, 2023
CSRF token reuse vulnerability in github.com/gofiber/fiber/v2 A cross-site request forgery vulnerability in this package can allow an attacker to inject arbitrary values and forge malicious requests on behalf of a user. The attacker may inject arbitrary values without any authentication, or perform various malicious actions on behalf of an authenticated user, potentially compromising the security and integrity of the application. The vulnerability is caused by improper validation and enforcement of CSRF tokens within the application. For 'safe' methods, the token is extracted from the cookie and saved to storage without further validation or sanitization. In addition, the CSRF token is validated against tokens in storage but not associated with a session, nor by using a Double Submit Cookie Method, allowing for token reuse. Fixed in
2.50.0
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-41338
GO-2023-2052
GHSA-3q5p-3558-364f
Sep 12, 2023
IsFromLocal local address check can be circumvented in github.com/gofiber/fiber/v2 The Ctx.IsFromLocal function can incorrectly report a request as being sent from localhost when the request contains an X-Forwarded-For header containing a localhost IP address. Fixed in
2.49.2-0.20230906112033-b8c9ede6efa2
References Updated May 20, 2024 · Source: OSV.dev
CVE-2018-20744
GHSA-927h-x4qj-r242
GO-2023-1792
May 14, 2022
github.com/gofiber/fiber/v2 vulnerable to Origin Validation Error
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
The Olivier Poitrey Go CORS handler through 1.3.0 actively converts a wildcard CORS policy into reflecting an arbitrary Origin header value, which is incompatible with the CORS security design, and could lead to CORS misconfiguration security problems. Fixed in
2.43.0
References Updated May 20, 2024 · Source: OSV.dev |
v2.11.0
minor
Dependencies (2)
|
|
v2.10.0
minor
11 CVEs
CVE-2026-42554
GO-2026-5585
GHSA-qjv7-627w-8qjv
Jul 24, 2026
Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fixed in
2.52.13
Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-45045
GHSA-gcfq-8gqf-4876
GO-2026-5887
Jul 02, 2026
GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryThe Vulnerable CodeFile:
Data Flow
Impact
FixReplace
Fixed in
2.52.14
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25882
GO-2026-4543
GHSA-mrq8-rjmw-wpq3
Feb 26, 2026
Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fixed in
2.52.12
References Updated Feb 26, 2026 · Source: OSV.dev
CVE-2025-66630
GO-2026-4471
GHSA-68rr-p4fp-j59v
Feb 19, 2026
Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() on crypto/rand failure in github.com/gofiber/fiber Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() — predictable / zero‑UUID on crypto/rand failure in github.com/gofiber/fiber Fixed in
2.52.11
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-54801
GO-2025-3845
GHSA-qx2q-88mx-vhg7
Aug 11, 2025
Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fixed in
2.52.9
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-38513
GO-2024-2959
GHSA-98j2-3j3p-fw2v
Jul 02, 2024
Session Middleware Token Injection Vulnerability in github.com/gofiber/fiber Session Middleware Token Injection Vulnerability in github.com/gofiber/fiber Fixed in
2.52.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-25124
GO-2024-2574
GHSA-fmg4-x8pw-hjhg
May 20, 2024
Insecure CORS Configuration allowing wildcard origin with credentials in github.com/gofiber/fiber/v2 The CORS middleware allows for insecure configurations that could potentially expose the application to multiple CORS-related vulnerabilities. Specifically, it allows setting the Access-Control-Allow-Origin header to a wildcard ("*") while also having the Access-Control-Allow-Credentials set to true, which goes against recommended security best practices. Fixed in
2.52.1
References
Updated May 20, 2024 · Source: OSV.dev
CVE-2023-45141
GO-2023-2116
GHSA-mv73-f69x-444p
Oct 24, 2023
CSRF token validation vulnerability in github.com/gofiber/fiber/v2 A cross-site request forgery vulnerability can allow an attacker to obtain tokens and forge malicious requests on behalf of a user. This can lead to unauthorized actions being taken on the user's behalf, potentially compromising the security and integrity of the application. The vulnerability is caused by improper validation and enforcement of CSRF tokens within the application. The CSRF token is validated against tokens in storage but was is not tied to the original requestor that generated it, allowing for token reuse. Fixed in
2.50.0
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-45128
GO-2023-2115
GHSA-94w9-97p3-p368
Oct 24, 2023
CSRF token reuse vulnerability in github.com/gofiber/fiber/v2 A cross-site request forgery vulnerability in this package can allow an attacker to inject arbitrary values and forge malicious requests on behalf of a user. The attacker may inject arbitrary values without any authentication, or perform various malicious actions on behalf of an authenticated user, potentially compromising the security and integrity of the application. The vulnerability is caused by improper validation and enforcement of CSRF tokens within the application. For 'safe' methods, the token is extracted from the cookie and saved to storage without further validation or sanitization. In addition, the CSRF token is validated against tokens in storage but not associated with a session, nor by using a Double Submit Cookie Method, allowing for token reuse. Fixed in
2.50.0
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-41338
GO-2023-2052
GHSA-3q5p-3558-364f
Sep 12, 2023
IsFromLocal local address check can be circumvented in github.com/gofiber/fiber/v2 The Ctx.IsFromLocal function can incorrectly report a request as being sent from localhost when the request contains an X-Forwarded-For header containing a localhost IP address. Fixed in
2.49.2-0.20230906112033-b8c9ede6efa2
References Updated May 20, 2024 · Source: OSV.dev
CVE-2018-20744
GHSA-927h-x4qj-r242
GO-2023-1792
May 14, 2022
github.com/gofiber/fiber/v2 vulnerable to Origin Validation Error
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
The Olivier Poitrey Go CORS handler through 1.3.0 actively converts a wildcard CORS policy into reflecting an arbitrary Origin header value, which is incompatible with the CORS security design, and could lead to CORS misconfiguration security problems. Fixed in
2.43.0
References Updated May 20, 2024 · Source: OSV.dev |
v2.10.0
minor
Dependencies (2)
|
|
v2.9.0
minor
11 CVEs
CVE-2026-42554
GO-2026-5585
GHSA-qjv7-627w-8qjv
Jul 24, 2026
Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fixed in
2.52.13
Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-45045
GHSA-gcfq-8gqf-4876
GO-2026-5887
Jul 02, 2026
GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryThe Vulnerable CodeFile:
Data Flow
Impact
FixReplace
Fixed in
2.52.14
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25882
GO-2026-4543
GHSA-mrq8-rjmw-wpq3
Feb 26, 2026
Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fixed in
2.52.12
References Updated Feb 26, 2026 · Source: OSV.dev
CVE-2025-66630
GO-2026-4471
GHSA-68rr-p4fp-j59v
Feb 19, 2026
Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() on crypto/rand failure in github.com/gofiber/fiber Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() — predictable / zero‑UUID on crypto/rand failure in github.com/gofiber/fiber Fixed in
2.52.11
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-54801
GO-2025-3845
GHSA-qx2q-88mx-vhg7
Aug 11, 2025
Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fixed in
2.52.9
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-38513
GO-2024-2959
GHSA-98j2-3j3p-fw2v
Jul 02, 2024
Session Middleware Token Injection Vulnerability in github.com/gofiber/fiber Session Middleware Token Injection Vulnerability in github.com/gofiber/fiber Fixed in
2.52.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-25124
GO-2024-2574
GHSA-fmg4-x8pw-hjhg
May 20, 2024
Insecure CORS Configuration allowing wildcard origin with credentials in github.com/gofiber/fiber/v2 The CORS middleware allows for insecure configurations that could potentially expose the application to multiple CORS-related vulnerabilities. Specifically, it allows setting the Access-Control-Allow-Origin header to a wildcard ("*") while also having the Access-Control-Allow-Credentials set to true, which goes against recommended security best practices. Fixed in
2.52.1
References
Updated May 20, 2024 · Source: OSV.dev
CVE-2023-45141
GO-2023-2116
GHSA-mv73-f69x-444p
Oct 24, 2023
CSRF token validation vulnerability in github.com/gofiber/fiber/v2 A cross-site request forgery vulnerability can allow an attacker to obtain tokens and forge malicious requests on behalf of a user. This can lead to unauthorized actions being taken on the user's behalf, potentially compromising the security and integrity of the application. The vulnerability is caused by improper validation and enforcement of CSRF tokens within the application. The CSRF token is validated against tokens in storage but was is not tied to the original requestor that generated it, allowing for token reuse. Fixed in
2.50.0
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-45128
GO-2023-2115
GHSA-94w9-97p3-p368
Oct 24, 2023
CSRF token reuse vulnerability in github.com/gofiber/fiber/v2 A cross-site request forgery vulnerability in this package can allow an attacker to inject arbitrary values and forge malicious requests on behalf of a user. The attacker may inject arbitrary values without any authentication, or perform various malicious actions on behalf of an authenticated user, potentially compromising the security and integrity of the application. The vulnerability is caused by improper validation and enforcement of CSRF tokens within the application. For 'safe' methods, the token is extracted from the cookie and saved to storage without further validation or sanitization. In addition, the CSRF token is validated against tokens in storage but not associated with a session, nor by using a Double Submit Cookie Method, allowing for token reuse. Fixed in
2.50.0
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-41338
GO-2023-2052
GHSA-3q5p-3558-364f
Sep 12, 2023
IsFromLocal local address check can be circumvented in github.com/gofiber/fiber/v2 The Ctx.IsFromLocal function can incorrectly report a request as being sent from localhost when the request contains an X-Forwarded-For header containing a localhost IP address. Fixed in
2.49.2-0.20230906112033-b8c9ede6efa2
References Updated May 20, 2024 · Source: OSV.dev
CVE-2018-20744
GHSA-927h-x4qj-r242
GO-2023-1792
May 14, 2022
github.com/gofiber/fiber/v2 vulnerable to Origin Validation Error
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
The Olivier Poitrey Go CORS handler through 1.3.0 actively converts a wildcard CORS policy into reflecting an arbitrary Origin header value, which is incompatible with the CORS security design, and could lead to CORS misconfiguration security problems. Fixed in
2.43.0
References Updated May 20, 2024 · Source: OSV.dev |
v2.9.0
minor
Dependencies (2)
|
|
v2.8.0
minor
11 CVEs
CVE-2026-42554
GO-2026-5585
GHSA-qjv7-627w-8qjv
Jul 24, 2026
Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fixed in
2.52.13
Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-45045
GHSA-gcfq-8gqf-4876
GO-2026-5887
Jul 02, 2026
GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryThe Vulnerable CodeFile:
Data Flow
Impact
FixReplace
Fixed in
2.52.14
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25882
GO-2026-4543
GHSA-mrq8-rjmw-wpq3
Feb 26, 2026
Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fixed in
2.52.12
References Updated Feb 26, 2026 · Source: OSV.dev
CVE-2025-66630
GO-2026-4471
GHSA-68rr-p4fp-j59v
Feb 19, 2026
Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() on crypto/rand failure in github.com/gofiber/fiber Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() — predictable / zero‑UUID on crypto/rand failure in github.com/gofiber/fiber Fixed in
2.52.11
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-54801
GO-2025-3845
GHSA-qx2q-88mx-vhg7
Aug 11, 2025
Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fixed in
2.52.9
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-38513
GO-2024-2959
GHSA-98j2-3j3p-fw2v
Jul 02, 2024
Session Middleware Token Injection Vulnerability in github.com/gofiber/fiber Session Middleware Token Injection Vulnerability in github.com/gofiber/fiber Fixed in
2.52.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-25124
GO-2024-2574
GHSA-fmg4-x8pw-hjhg
May 20, 2024
Insecure CORS Configuration allowing wildcard origin with credentials in github.com/gofiber/fiber/v2 The CORS middleware allows for insecure configurations that could potentially expose the application to multiple CORS-related vulnerabilities. Specifically, it allows setting the Access-Control-Allow-Origin header to a wildcard ("*") while also having the Access-Control-Allow-Credentials set to true, which goes against recommended security best practices. Fixed in
2.52.1
References
Updated May 20, 2024 · Source: OSV.dev
CVE-2023-45141
GO-2023-2116
GHSA-mv73-f69x-444p
Oct 24, 2023
CSRF token validation vulnerability in github.com/gofiber/fiber/v2 A cross-site request forgery vulnerability can allow an attacker to obtain tokens and forge malicious requests on behalf of a user. This can lead to unauthorized actions being taken on the user's behalf, potentially compromising the security and integrity of the application. The vulnerability is caused by improper validation and enforcement of CSRF tokens within the application. The CSRF token is validated against tokens in storage but was is not tied to the original requestor that generated it, allowing for token reuse. Fixed in
2.50.0
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-45128
GO-2023-2115
GHSA-94w9-97p3-p368
Oct 24, 2023
CSRF token reuse vulnerability in github.com/gofiber/fiber/v2 A cross-site request forgery vulnerability in this package can allow an attacker to inject arbitrary values and forge malicious requests on behalf of a user. The attacker may inject arbitrary values without any authentication, or perform various malicious actions on behalf of an authenticated user, potentially compromising the security and integrity of the application. The vulnerability is caused by improper validation and enforcement of CSRF tokens within the application. For 'safe' methods, the token is extracted from the cookie and saved to storage without further validation or sanitization. In addition, the CSRF token is validated against tokens in storage but not associated with a session, nor by using a Double Submit Cookie Method, allowing for token reuse. Fixed in
2.50.0
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-41338
GO-2023-2052
GHSA-3q5p-3558-364f
Sep 12, 2023
IsFromLocal local address check can be circumvented in github.com/gofiber/fiber/v2 The Ctx.IsFromLocal function can incorrectly report a request as being sent from localhost when the request contains an X-Forwarded-For header containing a localhost IP address. Fixed in
2.49.2-0.20230906112033-b8c9ede6efa2
References Updated May 20, 2024 · Source: OSV.dev
CVE-2018-20744
GHSA-927h-x4qj-r242
GO-2023-1792
May 14, 2022
github.com/gofiber/fiber/v2 vulnerable to Origin Validation Error
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
The Olivier Poitrey Go CORS handler through 1.3.0 actively converts a wildcard CORS policy into reflecting an arbitrary Origin header value, which is incompatible with the CORS security design, and could lead to CORS misconfiguration security problems. Fixed in
2.43.0
References Updated May 20, 2024 · Source: OSV.dev |
v2.8.0
minor
Dependencies (2)
|
|
v2.7.1
patch
11 CVEs
CVE-2026-42554
GO-2026-5585
GHSA-qjv7-627w-8qjv
Jul 24, 2026
Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fixed in
2.52.13
Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-45045
GHSA-gcfq-8gqf-4876
GO-2026-5887
Jul 02, 2026
GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryThe Vulnerable CodeFile:
Data Flow
Impact
FixReplace
Fixed in
2.52.14
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25882
GO-2026-4543
GHSA-mrq8-rjmw-wpq3
Feb 26, 2026
Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fixed in
2.52.12
References Updated Feb 26, 2026 · Source: OSV.dev
CVE-2025-66630
GO-2026-4471
GHSA-68rr-p4fp-j59v
Feb 19, 2026
Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() on crypto/rand failure in github.com/gofiber/fiber Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() — predictable / zero‑UUID on crypto/rand failure in github.com/gofiber/fiber Fixed in
2.52.11
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-54801
GO-2025-3845
GHSA-qx2q-88mx-vhg7
Aug 11, 2025
Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fixed in
2.52.9
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-38513
GO-2024-2959
GHSA-98j2-3j3p-fw2v
Jul 02, 2024
Session Middleware Token Injection Vulnerability in github.com/gofiber/fiber Session Middleware Token Injection Vulnerability in github.com/gofiber/fiber Fixed in
2.52.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-25124
GO-2024-2574
GHSA-fmg4-x8pw-hjhg
May 20, 2024
Insecure CORS Configuration allowing wildcard origin with credentials in github.com/gofiber/fiber/v2 The CORS middleware allows for insecure configurations that could potentially expose the application to multiple CORS-related vulnerabilities. Specifically, it allows setting the Access-Control-Allow-Origin header to a wildcard ("*") while also having the Access-Control-Allow-Credentials set to true, which goes against recommended security best practices. Fixed in
2.52.1
References
Updated May 20, 2024 · Source: OSV.dev
CVE-2023-45141
GO-2023-2116
GHSA-mv73-f69x-444p
Oct 24, 2023
CSRF token validation vulnerability in github.com/gofiber/fiber/v2 A cross-site request forgery vulnerability can allow an attacker to obtain tokens and forge malicious requests on behalf of a user. This can lead to unauthorized actions being taken on the user's behalf, potentially compromising the security and integrity of the application. The vulnerability is caused by improper validation and enforcement of CSRF tokens within the application. The CSRF token is validated against tokens in storage but was is not tied to the original requestor that generated it, allowing for token reuse. Fixed in
2.50.0
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-45128
GO-2023-2115
GHSA-94w9-97p3-p368
Oct 24, 2023
CSRF token reuse vulnerability in github.com/gofiber/fiber/v2 A cross-site request forgery vulnerability in this package can allow an attacker to inject arbitrary values and forge malicious requests on behalf of a user. The attacker may inject arbitrary values without any authentication, or perform various malicious actions on behalf of an authenticated user, potentially compromising the security and integrity of the application. The vulnerability is caused by improper validation and enforcement of CSRF tokens within the application. For 'safe' methods, the token is extracted from the cookie and saved to storage without further validation or sanitization. In addition, the CSRF token is validated against tokens in storage but not associated with a session, nor by using a Double Submit Cookie Method, allowing for token reuse. Fixed in
2.50.0
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-41338
GO-2023-2052
GHSA-3q5p-3558-364f
Sep 12, 2023
IsFromLocal local address check can be circumvented in github.com/gofiber/fiber/v2 The Ctx.IsFromLocal function can incorrectly report a request as being sent from localhost when the request contains an X-Forwarded-For header containing a localhost IP address. Fixed in
2.49.2-0.20230906112033-b8c9ede6efa2
References Updated May 20, 2024 · Source: OSV.dev
CVE-2018-20744
GHSA-927h-x4qj-r242
GO-2023-1792
May 14, 2022
github.com/gofiber/fiber/v2 vulnerable to Origin Validation Error
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
The Olivier Poitrey Go CORS handler through 1.3.0 actively converts a wildcard CORS policy into reflecting an arbitrary Origin header value, which is incompatible with the CORS security design, and could lead to CORS misconfiguration security problems. Fixed in
2.43.0
References Updated May 20, 2024 · Source: OSV.dev |
v2.7.1
patch
Dependencies (2)
|
|
v2.7.0
minor
11 CVEs
CVE-2026-42554
GO-2026-5585
GHSA-qjv7-627w-8qjv
Jul 24, 2026
Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fixed in
2.52.13
Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-45045
GHSA-gcfq-8gqf-4876
GO-2026-5887
Jul 02, 2026
GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryThe Vulnerable CodeFile:
Data Flow
Impact
FixReplace
Fixed in
2.52.14
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25882
GO-2026-4543
GHSA-mrq8-rjmw-wpq3
Feb 26, 2026
Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fixed in
2.52.12
References Updated Feb 26, 2026 · Source: OSV.dev
CVE-2025-66630
GO-2026-4471
GHSA-68rr-p4fp-j59v
Feb 19, 2026
Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() on crypto/rand failure in github.com/gofiber/fiber Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() — predictable / zero‑UUID on crypto/rand failure in github.com/gofiber/fiber Fixed in
2.52.11
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-54801
GO-2025-3845
GHSA-qx2q-88mx-vhg7
Aug 11, 2025
Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fixed in
2.52.9
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-38513
GO-2024-2959
GHSA-98j2-3j3p-fw2v
Jul 02, 2024
Session Middleware Token Injection Vulnerability in github.com/gofiber/fiber Session Middleware Token Injection Vulnerability in github.com/gofiber/fiber Fixed in
2.52.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-25124
GO-2024-2574
GHSA-fmg4-x8pw-hjhg
May 20, 2024
Insecure CORS Configuration allowing wildcard origin with credentials in github.com/gofiber/fiber/v2 The CORS middleware allows for insecure configurations that could potentially expose the application to multiple CORS-related vulnerabilities. Specifically, it allows setting the Access-Control-Allow-Origin header to a wildcard ("*") while also having the Access-Control-Allow-Credentials set to true, which goes against recommended security best practices. Fixed in
2.52.1
References
Updated May 20, 2024 · Source: OSV.dev
CVE-2023-45141
GO-2023-2116
GHSA-mv73-f69x-444p
Oct 24, 2023
CSRF token validation vulnerability in github.com/gofiber/fiber/v2 A cross-site request forgery vulnerability can allow an attacker to obtain tokens and forge malicious requests on behalf of a user. This can lead to unauthorized actions being taken on the user's behalf, potentially compromising the security and integrity of the application. The vulnerability is caused by improper validation and enforcement of CSRF tokens within the application. The CSRF token is validated against tokens in storage but was is not tied to the original requestor that generated it, allowing for token reuse. Fixed in
2.50.0
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-45128
GO-2023-2115
GHSA-94w9-97p3-p368
Oct 24, 2023
CSRF token reuse vulnerability in github.com/gofiber/fiber/v2 A cross-site request forgery vulnerability in this package can allow an attacker to inject arbitrary values and forge malicious requests on behalf of a user. The attacker may inject arbitrary values without any authentication, or perform various malicious actions on behalf of an authenticated user, potentially compromising the security and integrity of the application. The vulnerability is caused by improper validation and enforcement of CSRF tokens within the application. For 'safe' methods, the token is extracted from the cookie and saved to storage without further validation or sanitization. In addition, the CSRF token is validated against tokens in storage but not associated with a session, nor by using a Double Submit Cookie Method, allowing for token reuse. Fixed in
2.50.0
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-41338
GO-2023-2052
GHSA-3q5p-3558-364f
Sep 12, 2023
IsFromLocal local address check can be circumvented in github.com/gofiber/fiber/v2 The Ctx.IsFromLocal function can incorrectly report a request as being sent from localhost when the request contains an X-Forwarded-For header containing a localhost IP address. Fixed in
2.49.2-0.20230906112033-b8c9ede6efa2
References Updated May 20, 2024 · Source: OSV.dev
CVE-2018-20744
GHSA-927h-x4qj-r242
GO-2023-1792
May 14, 2022
github.com/gofiber/fiber/v2 vulnerable to Origin Validation Error
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
The Olivier Poitrey Go CORS handler through 1.3.0 actively converts a wildcard CORS policy into reflecting an arbitrary Origin header value, which is incompatible with the CORS security design, and could lead to CORS misconfiguration security problems. Fixed in
2.43.0
References Updated May 20, 2024 · Source: OSV.dev |
v2.7.0
minor
Dependencies (2)
|
|
v2.5.0
minor
11 CVEs
CVE-2026-42554
GO-2026-5585
GHSA-qjv7-627w-8qjv
Jul 24, 2026
Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fixed in
2.52.13
Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-45045
GHSA-gcfq-8gqf-4876
GO-2026-5887
Jul 02, 2026
GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryThe Vulnerable CodeFile:
Data Flow
Impact
FixReplace
Fixed in
2.52.14
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25882
GO-2026-4543
GHSA-mrq8-rjmw-wpq3
Feb 26, 2026
Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fixed in
2.52.12
References Updated Feb 26, 2026 · Source: OSV.dev
CVE-2025-66630
GO-2026-4471
GHSA-68rr-p4fp-j59v
Feb 19, 2026
Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() on crypto/rand failure in github.com/gofiber/fiber Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() — predictable / zero‑UUID on crypto/rand failure in github.com/gofiber/fiber Fixed in
2.52.11
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-54801
GO-2025-3845
GHSA-qx2q-88mx-vhg7
Aug 11, 2025
Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fixed in
2.52.9
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-38513
GO-2024-2959
GHSA-98j2-3j3p-fw2v
Jul 02, 2024
Session Middleware Token Injection Vulnerability in github.com/gofiber/fiber Session Middleware Token Injection Vulnerability in github.com/gofiber/fiber Fixed in
2.52.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-25124
GO-2024-2574
GHSA-fmg4-x8pw-hjhg
May 20, 2024
Insecure CORS Configuration allowing wildcard origin with credentials in github.com/gofiber/fiber/v2 The CORS middleware allows for insecure configurations that could potentially expose the application to multiple CORS-related vulnerabilities. Specifically, it allows setting the Access-Control-Allow-Origin header to a wildcard ("*") while also having the Access-Control-Allow-Credentials set to true, which goes against recommended security best practices. Fixed in
2.52.1
References
Updated May 20, 2024 · Source: OSV.dev
CVE-2023-45141
GO-2023-2116
GHSA-mv73-f69x-444p
Oct 24, 2023
CSRF token validation vulnerability in github.com/gofiber/fiber/v2 A cross-site request forgery vulnerability can allow an attacker to obtain tokens and forge malicious requests on behalf of a user. This can lead to unauthorized actions being taken on the user's behalf, potentially compromising the security and integrity of the application. The vulnerability is caused by improper validation and enforcement of CSRF tokens within the application. The CSRF token is validated against tokens in storage but was is not tied to the original requestor that generated it, allowing for token reuse. Fixed in
2.50.0
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-45128
GO-2023-2115
GHSA-94w9-97p3-p368
Oct 24, 2023
CSRF token reuse vulnerability in github.com/gofiber/fiber/v2 A cross-site request forgery vulnerability in this package can allow an attacker to inject arbitrary values and forge malicious requests on behalf of a user. The attacker may inject arbitrary values without any authentication, or perform various malicious actions on behalf of an authenticated user, potentially compromising the security and integrity of the application. The vulnerability is caused by improper validation and enforcement of CSRF tokens within the application. For 'safe' methods, the token is extracted from the cookie and saved to storage without further validation or sanitization. In addition, the CSRF token is validated against tokens in storage but not associated with a session, nor by using a Double Submit Cookie Method, allowing for token reuse. Fixed in
2.50.0
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-41338
GO-2023-2052
GHSA-3q5p-3558-364f
Sep 12, 2023
IsFromLocal local address check can be circumvented in github.com/gofiber/fiber/v2 The Ctx.IsFromLocal function can incorrectly report a request as being sent from localhost when the request contains an X-Forwarded-For header containing a localhost IP address. Fixed in
2.49.2-0.20230906112033-b8c9ede6efa2
References Updated May 20, 2024 · Source: OSV.dev
CVE-2018-20744
GHSA-927h-x4qj-r242
GO-2023-1792
May 14, 2022
github.com/gofiber/fiber/v2 vulnerable to Origin Validation Error
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
The Olivier Poitrey Go CORS handler through 1.3.0 actively converts a wildcard CORS policy into reflecting an arbitrary Origin header value, which is incompatible with the CORS security design, and could lead to CORS misconfiguration security problems. Fixed in
2.43.0
References Updated May 20, 2024 · Source: OSV.dev |
v2.5.0
minor
Dependencies (2)
|
|
v2.4.1
patch
11 CVEs
CVE-2026-42554
GO-2026-5585
GHSA-qjv7-627w-8qjv
Jul 24, 2026
Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fixed in
2.52.13
Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-45045
GHSA-gcfq-8gqf-4876
GO-2026-5887
Jul 02, 2026
GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryThe Vulnerable CodeFile:
Data Flow
Impact
FixReplace
Fixed in
2.52.14
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25882
GO-2026-4543
GHSA-mrq8-rjmw-wpq3
Feb 26, 2026
Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fixed in
2.52.12
References Updated Feb 26, 2026 · Source: OSV.dev
CVE-2025-66630
GO-2026-4471
GHSA-68rr-p4fp-j59v
Feb 19, 2026
Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() on crypto/rand failure in github.com/gofiber/fiber Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() — predictable / zero‑UUID on crypto/rand failure in github.com/gofiber/fiber Fixed in
2.52.11
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-54801
GO-2025-3845
GHSA-qx2q-88mx-vhg7
Aug 11, 2025
Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber Fixed in
2.52.9
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-38513
GO-2024-2959
GHSA-98j2-3j3p-fw2v
Jul 02, 2024
Session Middleware Token Injection Vulnerability in github.com/gofiber/fiber Session Middleware Token Injection Vulnerability in github.com/gofiber/fiber Fixed in
2.52.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-25124
GO-2024-2574
GHSA-fmg4-x8pw-hjhg
May 20, 2024
Insecure CORS Configuration allowing wildcard origin with credentials in github.com/gofiber/fiber/v2 The CORS middleware allows for insecure configurations that could potentially expose the application to multiple CORS-related vulnerabilities. Specifically, it allows setting the Access-Control-Allow-Origin header to a wildcard ("*") while also having the Access-Control-Allow-Credentials set to true, which goes against recommended security best practices. Fixed in
2.52.1
References
Updated May 20, 2024 · Source: OSV.dev
CVE-2023-45141
GO-2023-2116
GHSA-mv73-f69x-444p
Oct 24, 2023
CSRF token validation vulnerability in github.com/gofiber/fiber/v2 A cross-site request forgery vulnerability can allow an attacker to obtain tokens and forge malicious requests on behalf of a user. This can lead to unauthorized actions being taken on the user's behalf, potentially compromising the security and integrity of the application. The vulnerability is caused by improper validation and enforcement of CSRF tokens within the application. The CSRF token is validated against tokens in storage but was is not tied to the original requestor that generated it, allowing for token reuse. Fixed in
2.50.0
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-45128
GO-2023-2115
GHSA-94w9-97p3-p368
Oct 24, 2023
CSRF token reuse vulnerability in github.com/gofiber/fiber/v2 A cross-site request forgery vulnerability in this package can allow an attacker to inject arbitrary values and forge malicious requests on behalf of a user. The attacker may inject arbitrary values without any authentication, or perform various malicious actions on behalf of an authenticated user, potentially compromising the security and integrity of the application. The vulnerability is caused by improper validation and enforcement of CSRF tokens within the application. For 'safe' methods, the token is extracted from the cookie and saved to storage without further validation or sanitization. In addition, the CSRF token is validated against tokens in storage but not associated with a session, nor by using a Double Submit Cookie Method, allowing for token reuse. Fixed in
2.50.0
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-41338
GO-2023-2052
GHSA-3q5p-3558-364f
Sep 12, 2023
IsFromLocal local address check can be circumvented in github.com/gofiber/fiber/v2 The Ctx.IsFromLocal function can incorrectly report a request as being sent from localhost when the request contains an X-Forwarded-For header containing a localhost IP address. Fixed in
2.49.2-0.20230906112033-b8c9ede6efa2
References Updated May 20, 2024 · Source: OSV.dev
CVE-2018-20744
GHSA-927h-x4qj-r242
GO-2023-1792
May 14, 2022
github.com/gofiber/fiber/v2 vulnerable to Origin Validation Error
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
The Olivier Poitrey Go CORS handler through 1.3.0 actively converts a wildcard CORS policy into reflecting an arbitrary Origin header value, which is incompatible with the CORS security design, and could lead to CORS misconfiguration security problems. Fixed in
2.43.0
References Updated May 20, 2024 · Source: OSV.dev |
v2.4.1
patch
Dependencies (2)
|