github.com/gofiber/fiber/v3
⚡️ Express inspired web framework written in Go
Activity
- Latest release
- 1mo ago
- Total releases
- 13
- Cadence
- ~2 months
- Last 12 months
- 7
Reach
- Stars
- 40.1k
Details
- First release
- Apr 07, 2024
| Version | Released | |
|---|---|---|
v3.5.0
minor
|
v3.5.0
minor
Dependencies (14)
+ 6 more |
|
v3.4.0
minor
|
v3.4.0
minor
Dependencies (14)
+ 6 more |
|
v3.3.0
minor
1 CVE
CVE-2026-53624
GO-2026-5912
GHSA-gv83-gqw6-9j2c
Jul 24, 2026
GoFiber never set HSTS header in helmet middleware due to incorrect protocol check in github.com/gofiber/fiber GoFiber never set HSTS header in helmet middleware due to incorrect protocol check in github.com/gofiber/fiber Fixed in
3.4.0
References Updated Jul 24, 2026 · Source: OSV.dev |
v3.3.0
minor
Dependencies (14)
+ 6 more |
|
v3.2.0
minor
3 CVEs
CVE-2026-44332
GO-2026-5886
GHSA-g5vh-55hw-rxm8
Jul 24, 2026
GoFiber Vulnerable to Username Enumeration via Timing Oracle in BasicAuth Default Authorizer in github.com/gofiber/fiber GoFiber Vulnerable to Username Enumeration via Timing Oracle in BasicAuth Default Authorizer in github.com/gofiber/fiber Fixed in
3.3.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-53624
GO-2026-5912
GHSA-gv83-gqw6-9j2c
Jul 24, 2026
GoFiber never set HSTS header in helmet middleware due to incorrect protocol check in github.com/gofiber/fiber GoFiber never set HSTS header in helmet middleware due to incorrect protocol check in github.com/gofiber/fiber Fixed in
3.4.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-45045
GO-2026-5887
GHSA-gcfq-8gqf-4876
Jul 24, 2026
GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward in github.com/gofiber/fiber GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward in github.com/gofiber/fiber Fixed in
3.3.0
References Updated Jul 24, 2026 · Source: OSV.dev |
v3.2.0
minor
Dependencies (14)
+ 6 more |
|
v3.1.0
minor
5 CVEs
CVE-2026-30246
GO-2026-5069
GHSA-35hp-hqmv-8qg8
Jul 24, 2026
Fiber: Cache middleware key generator ignores query string in github.com/gofiber/fiber Fiber: Cache middleware key generator ignores query string in github.com/gofiber/fiber Fixed in
3.2.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-44332
GO-2026-5886
GHSA-g5vh-55hw-rxm8
Jul 24, 2026
GoFiber Vulnerable to Username Enumeration via Timing Oracle in BasicAuth Default Authorizer in github.com/gofiber/fiber GoFiber Vulnerable to Username Enumeration via Timing Oracle in BasicAuth Default Authorizer in github.com/gofiber/fiber Fixed in
3.3.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-53624
GO-2026-5912
GHSA-gv83-gqw6-9j2c
Jul 24, 2026
GoFiber never set HSTS header in helmet middleware due to incorrect protocol check in github.com/gofiber/fiber GoFiber never set HSTS header in helmet middleware due to incorrect protocol check in github.com/gofiber/fiber Fixed in
3.4.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-42554
GO-2026-5585
GHSA-qjv7-627w-8qjv
Jul 24, 2026
Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fixed in
3.2.0
Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-45045
GO-2026-5887
GHSA-gcfq-8gqf-4876
Jul 24, 2026
GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward in github.com/gofiber/fiber GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward in github.com/gofiber/fiber Fixed in
3.3.0
References Updated Jul 24, 2026 · Source: OSV.dev |
v3.1.0
minor
Dependencies (14)
+ 6 more |
|
v3.0.0
initial
8 CVEs
CVE-2026-30246
GO-2026-5069
GHSA-35hp-hqmv-8qg8
Jul 24, 2026
Fiber: Cache middleware key generator ignores query string in github.com/gofiber/fiber Fiber: Cache middleware key generator ignores query string in github.com/gofiber/fiber Fixed in
3.2.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-44332
GO-2026-5886
GHSA-g5vh-55hw-rxm8
Jul 24, 2026
GoFiber Vulnerable to Username Enumeration via Timing Oracle in BasicAuth Default Authorizer in github.com/gofiber/fiber GoFiber Vulnerable to Username Enumeration via Timing Oracle in BasicAuth Default Authorizer in github.com/gofiber/fiber Fixed in
3.3.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-53624
GO-2026-5912
GHSA-gv83-gqw6-9j2c
Jul 24, 2026
GoFiber never set HSTS header in helmet middleware due to incorrect protocol check in github.com/gofiber/fiber GoFiber never set HSTS header in helmet middleware due to incorrect protocol check in github.com/gofiber/fiber Fixed in
3.4.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-42554
GO-2026-5585
GHSA-qjv7-627w-8qjv
Jul 24, 2026
Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fixed in
3.2.0
Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-45045
GO-2026-5887
GHSA-gcfq-8gqf-4876
Jul 24, 2026
GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward in github.com/gofiber/fiber GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward in github.com/gofiber/fiber Fixed in
3.3.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-25899
GO-2026-4534
GHSA-2mr3-m5q5-wgp6
Feb 26, 2026
Fiber is Vulnerable to Denial of Service via Flash Cookie Unbounded Allocation in github.com/gofiber/fiber/v3 Fiber is Vulnerable to Denial of Service via Flash Cookie Unbounded Allocation in github.com/gofiber/fiber/v3 Fixed in
3.1.0
References Updated Feb 26, 2026 · Source: OSV.dev
CVE-2026-25891
GO-2026-4540
GHSA-m3c2-496v-cw3v
Feb 26, 2026
Fiber has an Arbitrary File Read in Static Middleware on Windows in github.com/gofiber/fiber/v3 Fiber has an Arbitrary File Read in Static Middleware on Windows in github.com/gofiber/fiber/v3 Fixed in
3.1.0
References Updated Feb 26, 2026 · Source: OSV.dev
CVE-2026-25882
GO-2026-4543
GHSA-mrq8-rjmw-wpq3
Feb 26, 2026
Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fixed in
3.1.0
References Updated Feb 26, 2026 · Source: OSV.dev |
v3.0.0
initial
Dependencies (14)
+ 6 more |
|
v3.0.0-rc.3
pre
8 CVEs
CVE-2026-30246
GO-2026-5069
GHSA-35hp-hqmv-8qg8
Jul 24, 2026
Fiber: Cache middleware key generator ignores query string in github.com/gofiber/fiber Fiber: Cache middleware key generator ignores query string in github.com/gofiber/fiber Fixed in
3.2.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-44332
GO-2026-5886
GHSA-g5vh-55hw-rxm8
Jul 24, 2026
GoFiber Vulnerable to Username Enumeration via Timing Oracle in BasicAuth Default Authorizer in github.com/gofiber/fiber GoFiber Vulnerable to Username Enumeration via Timing Oracle in BasicAuth Default Authorizer in github.com/gofiber/fiber Fixed in
3.3.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-53624
GO-2026-5912
GHSA-gv83-gqw6-9j2c
Jul 24, 2026
GoFiber never set HSTS header in helmet middleware due to incorrect protocol check in github.com/gofiber/fiber GoFiber never set HSTS header in helmet middleware due to incorrect protocol check in github.com/gofiber/fiber Fixed in
3.4.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-42554
GO-2026-5585
GHSA-qjv7-627w-8qjv
Jul 24, 2026
Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fixed in
3.2.0
Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-45045
GO-2026-5887
GHSA-gcfq-8gqf-4876
Jul 24, 2026
GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward in github.com/gofiber/fiber GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward in github.com/gofiber/fiber Fixed in
3.3.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-25899
GO-2026-4534
GHSA-2mr3-m5q5-wgp6
Feb 26, 2026
Fiber is Vulnerable to Denial of Service via Flash Cookie Unbounded Allocation in github.com/gofiber/fiber/v3 Fiber is Vulnerable to Denial of Service via Flash Cookie Unbounded Allocation in github.com/gofiber/fiber/v3 Fixed in
3.1.0
References Updated Feb 26, 2026 · Source: OSV.dev
CVE-2026-25891
GO-2026-4540
GHSA-m3c2-496v-cw3v
Feb 26, 2026
Fiber has an Arbitrary File Read in Static Middleware on Windows in github.com/gofiber/fiber/v3 Fiber has an Arbitrary File Read in Static Middleware on Windows in github.com/gofiber/fiber/v3 Fixed in
3.1.0
References Updated Feb 26, 2026 · Source: OSV.dev
CVE-2026-25882
GO-2026-4543
GHSA-mrq8-rjmw-wpq3
Feb 26, 2026
Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fixed in
3.1.0
References Updated Feb 26, 2026 · Source: OSV.dev |
v3.0.0-rc.3
pre
Dependencies (14)
+ 6 more |
|
v3.0.0-rc.2
pre
8 CVEs
CVE-2026-30246
GO-2026-5069
GHSA-35hp-hqmv-8qg8
Jul 24, 2026
Fiber: Cache middleware key generator ignores query string in github.com/gofiber/fiber Fiber: Cache middleware key generator ignores query string in github.com/gofiber/fiber Fixed in
3.2.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-44332
GO-2026-5886
GHSA-g5vh-55hw-rxm8
Jul 24, 2026
GoFiber Vulnerable to Username Enumeration via Timing Oracle in BasicAuth Default Authorizer in github.com/gofiber/fiber GoFiber Vulnerable to Username Enumeration via Timing Oracle in BasicAuth Default Authorizer in github.com/gofiber/fiber Fixed in
3.3.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-53624
GO-2026-5912
GHSA-gv83-gqw6-9j2c
Jul 24, 2026
GoFiber never set HSTS header in helmet middleware due to incorrect protocol check in github.com/gofiber/fiber GoFiber never set HSTS header in helmet middleware due to incorrect protocol check in github.com/gofiber/fiber Fixed in
3.4.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-42554
GO-2026-5585
GHSA-qjv7-627w-8qjv
Jul 24, 2026
Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fixed in
3.2.0
Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-45045
GO-2026-5887
GHSA-gcfq-8gqf-4876
Jul 24, 2026
GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward in github.com/gofiber/fiber GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward in github.com/gofiber/fiber Fixed in
3.3.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-25899
GO-2026-4534
GHSA-2mr3-m5q5-wgp6
Feb 26, 2026
Fiber is Vulnerable to Denial of Service via Flash Cookie Unbounded Allocation in github.com/gofiber/fiber/v3 Fiber is Vulnerable to Denial of Service via Flash Cookie Unbounded Allocation in github.com/gofiber/fiber/v3 Fixed in
3.1.0
References Updated Feb 26, 2026 · Source: OSV.dev
CVE-2026-25891
GO-2026-4540
GHSA-m3c2-496v-cw3v
Feb 26, 2026
Fiber has an Arbitrary File Read in Static Middleware on Windows in github.com/gofiber/fiber/v3 Fiber has an Arbitrary File Read in Static Middleware on Windows in github.com/gofiber/fiber/v3 Fixed in
3.1.0
References Updated Feb 26, 2026 · Source: OSV.dev
CVE-2026-25882
GO-2026-4543
GHSA-mrq8-rjmw-wpq3
Feb 26, 2026
Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fixed in
3.1.0
References Updated Feb 26, 2026 · Source: OSV.dev |
v3.0.0-rc.2
pre
Dependencies (14)
+ 6 more |
|
v3.0.0-rc.1
pre
8 CVEs
CVE-2026-30246
GO-2026-5069
GHSA-35hp-hqmv-8qg8
Jul 24, 2026
Fiber: Cache middleware key generator ignores query string in github.com/gofiber/fiber Fiber: Cache middleware key generator ignores query string in github.com/gofiber/fiber Fixed in
3.2.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-44332
GO-2026-5886
GHSA-g5vh-55hw-rxm8
Jul 24, 2026
GoFiber Vulnerable to Username Enumeration via Timing Oracle in BasicAuth Default Authorizer in github.com/gofiber/fiber GoFiber Vulnerable to Username Enumeration via Timing Oracle in BasicAuth Default Authorizer in github.com/gofiber/fiber Fixed in
3.3.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-53624
GO-2026-5912
GHSA-gv83-gqw6-9j2c
Jul 24, 2026
GoFiber never set HSTS header in helmet middleware due to incorrect protocol check in github.com/gofiber/fiber GoFiber never set HSTS header in helmet middleware due to incorrect protocol check in github.com/gofiber/fiber Fixed in
3.4.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-42554
GO-2026-5585
GHSA-qjv7-627w-8qjv
Jul 24, 2026
Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fixed in
3.2.0
Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-45045
GO-2026-5887
GHSA-gcfq-8gqf-4876
Jul 24, 2026
GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward in github.com/gofiber/fiber GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward in github.com/gofiber/fiber Fixed in
3.3.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-25899
GO-2026-4534
GHSA-2mr3-m5q5-wgp6
Feb 26, 2026
Fiber is Vulnerable to Denial of Service via Flash Cookie Unbounded Allocation in github.com/gofiber/fiber/v3 Fiber is Vulnerable to Denial of Service via Flash Cookie Unbounded Allocation in github.com/gofiber/fiber/v3 Fixed in
3.1.0
References Updated Feb 26, 2026 · Source: OSV.dev
CVE-2026-25891
GO-2026-4540
GHSA-m3c2-496v-cw3v
Feb 26, 2026
Fiber has an Arbitrary File Read in Static Middleware on Windows in github.com/gofiber/fiber/v3 Fiber has an Arbitrary File Read in Static Middleware on Windows in github.com/gofiber/fiber/v3 Fixed in
3.1.0
References Updated Feb 26, 2026 · Source: OSV.dev
CVE-2026-25882
GO-2026-4543
GHSA-mrq8-rjmw-wpq3
Feb 26, 2026
Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fixed in
3.1.0
References Updated Feb 26, 2026 · Source: OSV.dev |
v3.0.0-rc.1
pre
Dependencies (13)
+ 5 more |
|
v3.0.0-beta.5
pre
8 CVEs
CVE-2026-30246
GO-2026-5069
GHSA-35hp-hqmv-8qg8
Jul 24, 2026
Fiber: Cache middleware key generator ignores query string in github.com/gofiber/fiber Fiber: Cache middleware key generator ignores query string in github.com/gofiber/fiber Fixed in
3.2.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-44332
GO-2026-5886
GHSA-g5vh-55hw-rxm8
Jul 24, 2026
GoFiber Vulnerable to Username Enumeration via Timing Oracle in BasicAuth Default Authorizer in github.com/gofiber/fiber GoFiber Vulnerable to Username Enumeration via Timing Oracle in BasicAuth Default Authorizer in github.com/gofiber/fiber Fixed in
3.3.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-53624
GO-2026-5912
GHSA-gv83-gqw6-9j2c
Jul 24, 2026
GoFiber never set HSTS header in helmet middleware due to incorrect protocol check in github.com/gofiber/fiber GoFiber never set HSTS header in helmet middleware due to incorrect protocol check in github.com/gofiber/fiber Fixed in
3.4.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-42554
GO-2026-5585
GHSA-qjv7-627w-8qjv
Jul 24, 2026
Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fixed in
3.2.0
Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-45045
GO-2026-5887
GHSA-gcfq-8gqf-4876
Jul 24, 2026
GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward in github.com/gofiber/fiber GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward in github.com/gofiber/fiber Fixed in
3.3.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-25899
GO-2026-4534
GHSA-2mr3-m5q5-wgp6
Feb 26, 2026
Fiber is Vulnerable to Denial of Service via Flash Cookie Unbounded Allocation in github.com/gofiber/fiber/v3 Fiber is Vulnerable to Denial of Service via Flash Cookie Unbounded Allocation in github.com/gofiber/fiber/v3 Fixed in
3.1.0
References Updated Feb 26, 2026 · Source: OSV.dev
CVE-2026-25891
GO-2026-4540
GHSA-m3c2-496v-cw3v
Feb 26, 2026
Fiber has an Arbitrary File Read in Static Middleware on Windows in github.com/gofiber/fiber/v3 Fiber has an Arbitrary File Read in Static Middleware on Windows in github.com/gofiber/fiber/v3 Fixed in
3.1.0
References Updated Feb 26, 2026 · Source: OSV.dev
CVE-2026-25882
GO-2026-4543
GHSA-mrq8-rjmw-wpq3
Feb 26, 2026
Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fixed in
3.1.0
References Updated Feb 26, 2026 · Source: OSV.dev |
v3.0.0-beta.5
pre
Dependencies (13)
+ 5 more |
|
v3.0.0-beta.4
pre
8 CVEs
CVE-2026-30246
GO-2026-5069
GHSA-35hp-hqmv-8qg8
Jul 24, 2026
Fiber: Cache middleware key generator ignores query string in github.com/gofiber/fiber Fiber: Cache middleware key generator ignores query string in github.com/gofiber/fiber Fixed in
3.2.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-44332
GO-2026-5886
GHSA-g5vh-55hw-rxm8
Jul 24, 2026
GoFiber Vulnerable to Username Enumeration via Timing Oracle in BasicAuth Default Authorizer in github.com/gofiber/fiber GoFiber Vulnerable to Username Enumeration via Timing Oracle in BasicAuth Default Authorizer in github.com/gofiber/fiber Fixed in
3.3.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-53624
GO-2026-5912
GHSA-gv83-gqw6-9j2c
Jul 24, 2026
GoFiber never set HSTS header in helmet middleware due to incorrect protocol check in github.com/gofiber/fiber GoFiber never set HSTS header in helmet middleware due to incorrect protocol check in github.com/gofiber/fiber Fixed in
3.4.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-42554
GO-2026-5585
GHSA-qjv7-627w-8qjv
Jul 24, 2026
Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fixed in
3.2.0
Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-45045
GO-2026-5887
GHSA-gcfq-8gqf-4876
Jul 24, 2026
GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward in github.com/gofiber/fiber GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward in github.com/gofiber/fiber Fixed in
3.3.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-25899
GO-2026-4534
GHSA-2mr3-m5q5-wgp6
Feb 26, 2026
Fiber is Vulnerable to Denial of Service via Flash Cookie Unbounded Allocation in github.com/gofiber/fiber/v3 Fiber is Vulnerable to Denial of Service via Flash Cookie Unbounded Allocation in github.com/gofiber/fiber/v3 Fixed in
3.1.0
References Updated Feb 26, 2026 · Source: OSV.dev
CVE-2026-25891
GO-2026-4540
GHSA-m3c2-496v-cw3v
Feb 26, 2026
Fiber has an Arbitrary File Read in Static Middleware on Windows in github.com/gofiber/fiber/v3 Fiber has an Arbitrary File Read in Static Middleware on Windows in github.com/gofiber/fiber/v3 Fixed in
3.1.0
References Updated Feb 26, 2026 · Source: OSV.dev
CVE-2026-25882
GO-2026-4543
GHSA-mrq8-rjmw-wpq3
Feb 26, 2026
Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fixed in
3.1.0
References Updated Feb 26, 2026 · Source: OSV.dev |
v3.0.0-beta.4
pre
Dependencies (11)
+ 3 more |
|
v3.0.0-beta.3
pre
8 CVEs
CVE-2026-30246
GO-2026-5069
GHSA-35hp-hqmv-8qg8
Jul 24, 2026
Fiber: Cache middleware key generator ignores query string in github.com/gofiber/fiber Fiber: Cache middleware key generator ignores query string in github.com/gofiber/fiber Fixed in
3.2.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-44332
GO-2026-5886
GHSA-g5vh-55hw-rxm8
Jul 24, 2026
GoFiber Vulnerable to Username Enumeration via Timing Oracle in BasicAuth Default Authorizer in github.com/gofiber/fiber GoFiber Vulnerable to Username Enumeration via Timing Oracle in BasicAuth Default Authorizer in github.com/gofiber/fiber Fixed in
3.3.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-53624
GO-2026-5912
GHSA-gv83-gqw6-9j2c
Jul 24, 2026
GoFiber never set HSTS header in helmet middleware due to incorrect protocol check in github.com/gofiber/fiber GoFiber never set HSTS header in helmet middleware due to incorrect protocol check in github.com/gofiber/fiber Fixed in
3.4.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-42554
GO-2026-5585
GHSA-qjv7-627w-8qjv
Jul 24, 2026
Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fixed in
3.2.0
Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-45045
GO-2026-5887
GHSA-gcfq-8gqf-4876
Jul 24, 2026
GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward in github.com/gofiber/fiber GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward in github.com/gofiber/fiber Fixed in
3.3.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-25899
GO-2026-4534
GHSA-2mr3-m5q5-wgp6
Feb 26, 2026
Fiber is Vulnerable to Denial of Service via Flash Cookie Unbounded Allocation in github.com/gofiber/fiber/v3 Fiber is Vulnerable to Denial of Service via Flash Cookie Unbounded Allocation in github.com/gofiber/fiber/v3 Fixed in
3.1.0
References Updated Feb 26, 2026 · Source: OSV.dev
CVE-2026-25891
GO-2026-4540
GHSA-m3c2-496v-cw3v
Feb 26, 2026
Fiber has an Arbitrary File Read in Static Middleware on Windows in github.com/gofiber/fiber/v3 Fiber has an Arbitrary File Read in Static Middleware on Windows in github.com/gofiber/fiber/v3 Fixed in
3.1.0
References Updated Feb 26, 2026 · Source: OSV.dev
CVE-2026-25882
GO-2026-4543
GHSA-mrq8-rjmw-wpq3
Feb 26, 2026
Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fixed in
3.1.0
References Updated Feb 26, 2026 · Source: OSV.dev |
v3.0.0-beta.3
pre
Dependencies (8)
|
|
v3.0.0-beta.2
pre
8 CVEs
CVE-2026-30246
GO-2026-5069
GHSA-35hp-hqmv-8qg8
Jul 24, 2026
Fiber: Cache middleware key generator ignores query string in github.com/gofiber/fiber Fiber: Cache middleware key generator ignores query string in github.com/gofiber/fiber Fixed in
3.2.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-44332
GO-2026-5886
GHSA-g5vh-55hw-rxm8
Jul 24, 2026
GoFiber Vulnerable to Username Enumeration via Timing Oracle in BasicAuth Default Authorizer in github.com/gofiber/fiber GoFiber Vulnerable to Username Enumeration via Timing Oracle in BasicAuth Default Authorizer in github.com/gofiber/fiber Fixed in
3.3.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-53624
GO-2026-5912
GHSA-gv83-gqw6-9j2c
Jul 24, 2026
GoFiber never set HSTS header in helmet middleware due to incorrect protocol check in github.com/gofiber/fiber GoFiber never set HSTS header in helmet middleware due to incorrect protocol check in github.com/gofiber/fiber Fixed in
3.4.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-42554
GO-2026-5585
GHSA-qjv7-627w-8qjv
Jul 24, 2026
Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fiber vulnerable to XSS in AutoFormat Content Negotiation in github.com/gofiber/fiber Fixed in
3.2.0
Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-45045
GO-2026-5887
GHSA-gcfq-8gqf-4876
Jul 24, 2026
GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward in github.com/gofiber/fiber GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward in github.com/gofiber/fiber Fixed in
3.3.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-25899
GO-2026-4534
GHSA-2mr3-m5q5-wgp6
Feb 26, 2026
Fiber is Vulnerable to Denial of Service via Flash Cookie Unbounded Allocation in github.com/gofiber/fiber/v3 Fiber is Vulnerable to Denial of Service via Flash Cookie Unbounded Allocation in github.com/gofiber/fiber/v3 Fixed in
3.1.0
References Updated Feb 26, 2026 · Source: OSV.dev
CVE-2026-25891
GO-2026-4540
GHSA-m3c2-496v-cw3v
Feb 26, 2026
Fiber has an Arbitrary File Read in Static Middleware on Windows in github.com/gofiber/fiber/v3 Fiber has an Arbitrary File Read in Static Middleware on Windows in github.com/gofiber/fiber/v3 Fixed in
3.1.0
References Updated Feb 26, 2026 · Source: OSV.dev
CVE-2026-25882
GO-2026-4543
GHSA-mrq8-rjmw-wpq3
Feb 26, 2026
Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber Fixed in
3.1.0
References Updated Feb 26, 2026 · Source: OSV.dev |
v3.0.0-beta.2
pre
Dependencies (8)
|