github.com/valyala/fasthttp
Fast HTTP package for Go. Tuned for high performance. Zero memory allocations in hot paths. Up to 10x faster than net/http
Activity
- Latest release
- 1w ago
- Total releases
- 56
- Cadence
- ~37 days
- Last 12 months
- 8
Reach
- Stars
- 23.5k
Details
- First release
- Jan 04, 2019
| Version | Released | |
|---|---|---|
v1.74.0
minor
|
v1.74.0
minor
Dependencies (6)
|
|
v1.73.0
minor
|
v1.73.0
minor
Dependencies (6)
|
|
v1.72.0
minor
|
v1.72.0
minor
Dependencies (6)
|
|
v1.71.0
minor
|
v1.71.0
minor
Dependencies (6)
|
|
v1.70.0
minor
|
v1.70.0
minor
Dependencies (6)
|
|
v1.69.0
minor
1 CVE
GO-2026-4950
Aug 18, 2026
Authorization bypass via double-encoded paths in github.com/valyala/fasthttp In github.com/valyala/fasthttp before 1.70.0, ServeFile and ServeFS reinterpret filesystem paths as URIs, decoding percent-encoded sequences and treating characters like '?' and '#' as URI delimiters. In applications where authorization guards inspect ctx.Path() before passing paths to file-serving handlers, double-encoded path variants (e.g., /%2561dmin/export.csv) bypass access controls while still resolving to the protected file on disk. Fixed in
1.70.0
References Updated Aug 19, 2026 · Source: OSV.dev |
v1.69.0
minor
Dependencies (6)
|
|
v1.68.0
minor
1 CVE
GO-2026-4950
Aug 18, 2026
Authorization bypass via double-encoded paths in github.com/valyala/fasthttp In github.com/valyala/fasthttp before 1.70.0, ServeFile and ServeFS reinterpret filesystem paths as URIs, decoding percent-encoded sequences and treating characters like '?' and '#' as URI delimiters. In applications where authorization guards inspect ctx.Path() before passing paths to file-serving handlers, double-encoded path variants (e.g., /%2561dmin/export.csv) bypass access controls while still resolving to the protected file on disk. Fixed in
1.70.0
References Updated Aug 19, 2026 · Source: OSV.dev |
v1.68.0
minor
Dependencies (6)
|
|
v1.67.0
minor
1 CVE
GO-2026-4950
Aug 18, 2026
Authorization bypass via double-encoded paths in github.com/valyala/fasthttp In github.com/valyala/fasthttp before 1.70.0, ServeFile and ServeFS reinterpret filesystem paths as URIs, decoding percent-encoded sequences and treating characters like '?' and '#' as URI delimiters. In applications where authorization guards inspect ctx.Path() before passing paths to file-serving handlers, double-encoded path variants (e.g., /%2561dmin/export.csv) bypass access controls while still resolving to the protected file on disk. Fixed in
1.70.0
References Updated Aug 19, 2026 · Source: OSV.dev |
v1.67.0
minor
Dependencies (6)
|
|
v1.66.0
minor
1 CVE
GO-2026-4950
Aug 18, 2026
Authorization bypass via double-encoded paths in github.com/valyala/fasthttp In github.com/valyala/fasthttp before 1.70.0, ServeFile and ServeFS reinterpret filesystem paths as URIs, decoding percent-encoded sequences and treating characters like '?' and '#' as URI delimiters. In applications where authorization guards inspect ctx.Path() before passing paths to file-serving handlers, double-encoded path variants (e.g., /%2561dmin/export.csv) bypass access controls while still resolving to the protected file on disk. Fixed in
1.70.0
References Updated Aug 19, 2026 · Source: OSV.dev |
v1.66.0
minor
Dependencies (6)
|
|
v1.65.0
minor
1 CVE
GO-2026-4950
Aug 18, 2026
Authorization bypass via double-encoded paths in github.com/valyala/fasthttp In github.com/valyala/fasthttp before 1.70.0, ServeFile and ServeFS reinterpret filesystem paths as URIs, decoding percent-encoded sequences and treating characters like '?' and '#' as URI delimiters. In applications where authorization guards inspect ctx.Path() before passing paths to file-serving handlers, double-encoded path variants (e.g., /%2561dmin/export.csv) bypass access controls while still resolving to the protected file on disk. Fixed in
1.70.0
References Updated Aug 19, 2026 · Source: OSV.dev |
v1.65.0
minor
Dependencies (6)
|
|
v1.64.0
minor
1 CVE
GO-2026-4950
Aug 18, 2026
Authorization bypass via double-encoded paths in github.com/valyala/fasthttp In github.com/valyala/fasthttp before 1.70.0, ServeFile and ServeFS reinterpret filesystem paths as URIs, decoding percent-encoded sequences and treating characters like '?' and '#' as URI delimiters. In applications where authorization guards inspect ctx.Path() before passing paths to file-serving handlers, double-encoded path variants (e.g., /%2561dmin/export.csv) bypass access controls while still resolving to the protected file on disk. Fixed in
1.70.0
References Updated Aug 19, 2026 · Source: OSV.dev |
v1.64.0
minor
Dependencies (6)
|
|
v1.63.0
minor
1 CVE
GO-2026-4950
Aug 18, 2026
Authorization bypass via double-encoded paths in github.com/valyala/fasthttp In github.com/valyala/fasthttp before 1.70.0, ServeFile and ServeFS reinterpret filesystem paths as URIs, decoding percent-encoded sequences and treating characters like '?' and '#' as URI delimiters. In applications where authorization guards inspect ctx.Path() before passing paths to file-serving handlers, double-encoded path variants (e.g., /%2561dmin/export.csv) bypass access controls while still resolving to the protected file on disk. Fixed in
1.70.0
References Updated Aug 19, 2026 · Source: OSV.dev |
v1.63.0
minor
Dependencies (6)
|
|
v1.62.0
minor
1 CVE
GO-2026-4950
Aug 18, 2026
Authorization bypass via double-encoded paths in github.com/valyala/fasthttp In github.com/valyala/fasthttp before 1.70.0, ServeFile and ServeFS reinterpret filesystem paths as URIs, decoding percent-encoded sequences and treating characters like '?' and '#' as URI delimiters. In applications where authorization guards inspect ctx.Path() before passing paths to file-serving handlers, double-encoded path variants (e.g., /%2561dmin/export.csv) bypass access controls while still resolving to the protected file on disk. Fixed in
1.70.0
References Updated Aug 19, 2026 · Source: OSV.dev |
v1.62.0
minor
Dependencies (6)
|
|
v1.61.0
minor
1 CVE
GO-2026-4950
Aug 18, 2026
Authorization bypass via double-encoded paths in github.com/valyala/fasthttp In github.com/valyala/fasthttp before 1.70.0, ServeFile and ServeFS reinterpret filesystem paths as URIs, decoding percent-encoded sequences and treating characters like '?' and '#' as URI delimiters. In applications where authorization guards inspect ctx.Path() before passing paths to file-serving handlers, double-encoded path variants (e.g., /%2561dmin/export.csv) bypass access controls while still resolving to the protected file on disk. Fixed in
1.70.0
References Updated Aug 19, 2026 · Source: OSV.dev |
v1.61.0
minor
Dependencies (6)
|
|
v1.60.0
minor
1 CVE
GO-2026-4950
Aug 18, 2026
Authorization bypass via double-encoded paths in github.com/valyala/fasthttp In github.com/valyala/fasthttp before 1.70.0, ServeFile and ServeFS reinterpret filesystem paths as URIs, decoding percent-encoded sequences and treating characters like '?' and '#' as URI delimiters. In applications where authorization guards inspect ctx.Path() before passing paths to file-serving handlers, double-encoded path variants (e.g., /%2561dmin/export.csv) bypass access controls while still resolving to the protected file on disk. Fixed in
1.70.0
References Updated Aug 19, 2026 · Source: OSV.dev |
v1.60.0
minor
Dependencies (6)
|
|
v1.59.0
minor
1 CVE
GO-2026-4950
Aug 18, 2026
Authorization bypass via double-encoded paths in github.com/valyala/fasthttp In github.com/valyala/fasthttp before 1.70.0, ServeFile and ServeFS reinterpret filesystem paths as URIs, decoding percent-encoded sequences and treating characters like '?' and '#' as URI delimiters. In applications where authorization guards inspect ctx.Path() before passing paths to file-serving handlers, double-encoded path variants (e.g., /%2561dmin/export.csv) bypass access controls while still resolving to the protected file on disk. Fixed in
1.70.0
References Updated Aug 19, 2026 · Source: OSV.dev |
v1.59.0
minor
Dependencies (6)
|
|
v1.58.0
minor
1 CVE
GO-2026-4950
Aug 18, 2026
Authorization bypass via double-encoded paths in github.com/valyala/fasthttp In github.com/valyala/fasthttp before 1.70.0, ServeFile and ServeFS reinterpret filesystem paths as URIs, decoding percent-encoded sequences and treating characters like '?' and '#' as URI delimiters. In applications where authorization guards inspect ctx.Path() before passing paths to file-serving handlers, double-encoded path variants (e.g., /%2561dmin/export.csv) bypass access controls while still resolving to the protected file on disk. Fixed in
1.70.0
References Updated Aug 19, 2026 · Source: OSV.dev |
v1.58.0
minor
Dependencies (7)
|
|
v1.57.0
minor
1 CVE
GO-2026-4950
Aug 18, 2026
Authorization bypass via double-encoded paths in github.com/valyala/fasthttp In github.com/valyala/fasthttp before 1.70.0, ServeFile and ServeFS reinterpret filesystem paths as URIs, decoding percent-encoded sequences and treating characters like '?' and '#' as URI delimiters. In applications where authorization guards inspect ctx.Path() before passing paths to file-serving handlers, double-encoded path variants (e.g., /%2561dmin/export.csv) bypass access controls while still resolving to the protected file on disk. Fixed in
1.70.0
References Updated Aug 19, 2026 · Source: OSV.dev |
v1.57.0
minor
Dependencies (7)
|
|
v1.56.0
minor
1 CVE
GO-2026-4950
Aug 18, 2026
Authorization bypass via double-encoded paths in github.com/valyala/fasthttp In github.com/valyala/fasthttp before 1.70.0, ServeFile and ServeFS reinterpret filesystem paths as URIs, decoding percent-encoded sequences and treating characters like '?' and '#' as URI delimiters. In applications where authorization guards inspect ctx.Path() before passing paths to file-serving handlers, double-encoded path variants (e.g., /%2561dmin/export.csv) bypass access controls while still resolving to the protected file on disk. Fixed in
1.70.0
References Updated Aug 19, 2026 · Source: OSV.dev |
v1.56.0
minor
Dependencies (7)
|
|
v1.55.0
minor
1 CVE
GO-2026-4950
Aug 18, 2026
Authorization bypass via double-encoded paths in github.com/valyala/fasthttp In github.com/valyala/fasthttp before 1.70.0, ServeFile and ServeFS reinterpret filesystem paths as URIs, decoding percent-encoded sequences and treating characters like '?' and '#' as URI delimiters. In applications where authorization guards inspect ctx.Path() before passing paths to file-serving handlers, double-encoded path variants (e.g., /%2561dmin/export.csv) bypass access controls while still resolving to the protected file on disk. Fixed in
1.70.0
References Updated Aug 19, 2026 · Source: OSV.dev |
v1.55.0
minor
Dependencies (7)
|
|
v1.54.0
minor
1 CVE
GO-2026-4950
Aug 18, 2026
Authorization bypass via double-encoded paths in github.com/valyala/fasthttp In github.com/valyala/fasthttp before 1.70.0, ServeFile and ServeFS reinterpret filesystem paths as URIs, decoding percent-encoded sequences and treating characters like '?' and '#' as URI delimiters. In applications where authorization guards inspect ctx.Path() before passing paths to file-serving handlers, double-encoded path variants (e.g., /%2561dmin/export.csv) bypass access controls while still resolving to the protected file on disk. Fixed in
1.70.0
References Updated Aug 19, 2026 · Source: OSV.dev |
v1.54.0
minor
Dependencies (7)
|
|
v1.53.0
minor
1 CVE
GO-2026-4950
Aug 18, 2026
Authorization bypass via double-encoded paths in github.com/valyala/fasthttp In github.com/valyala/fasthttp before 1.70.0, ServeFile and ServeFS reinterpret filesystem paths as URIs, decoding percent-encoded sequences and treating characters like '?' and '#' as URI delimiters. In applications where authorization guards inspect ctx.Path() before passing paths to file-serving handlers, double-encoded path variants (e.g., /%2561dmin/export.csv) bypass access controls while still resolving to the protected file on disk. Fixed in
1.70.0
References Updated Aug 19, 2026 · Source: OSV.dev |
v1.53.0
minor
Dependencies (7)
|
|
v1.51.0
minor
1 CVE
GO-2026-4950
Aug 18, 2026
Authorization bypass via double-encoded paths in github.com/valyala/fasthttp In github.com/valyala/fasthttp before 1.70.0, ServeFile and ServeFS reinterpret filesystem paths as URIs, decoding percent-encoded sequences and treating characters like '?' and '#' as URI delimiters. In applications where authorization guards inspect ctx.Path() before passing paths to file-serving handlers, double-encoded path variants (e.g., /%2561dmin/export.csv) bypass access controls while still resolving to the protected file on disk. Fixed in
1.70.0
References Updated Aug 19, 2026 · Source: OSV.dev |
v1.51.0
minor
Dependencies (7)
|
|
v1.50.0
minor
1 CVE
GO-2026-4950
Aug 18, 2026
Authorization bypass via double-encoded paths in github.com/valyala/fasthttp In github.com/valyala/fasthttp before 1.70.0, ServeFile and ServeFS reinterpret filesystem paths as URIs, decoding percent-encoded sequences and treating characters like '?' and '#' as URI delimiters. In applications where authorization guards inspect ctx.Path() before passing paths to file-serving handlers, double-encoded path variants (e.g., /%2561dmin/export.csv) bypass access controls while still resolving to the protected file on disk. Fixed in
1.70.0
References Updated Aug 19, 2026 · Source: OSV.dev |
v1.50.0
minor
Dependencies (7)
|
|
v1.49.0
minor
1 CVE
GO-2026-4950
Aug 18, 2026
Authorization bypass via double-encoded paths in github.com/valyala/fasthttp In github.com/valyala/fasthttp before 1.70.0, ServeFile and ServeFS reinterpret filesystem paths as URIs, decoding percent-encoded sequences and treating characters like '?' and '#' as URI delimiters. In applications where authorization guards inspect ctx.Path() before passing paths to file-serving handlers, double-encoded path variants (e.g., /%2561dmin/export.csv) bypass access controls while still resolving to the protected file on disk. Fixed in
1.70.0
References Updated Aug 19, 2026 · Source: OSV.dev |
v1.49.0
minor
Dependencies (7)
|
|
v1.48.0
minor
1 CVE
GO-2026-4950
Aug 18, 2026
Authorization bypass via double-encoded paths in github.com/valyala/fasthttp In github.com/valyala/fasthttp before 1.70.0, ServeFile and ServeFS reinterpret filesystem paths as URIs, decoding percent-encoded sequences and treating characters like '?' and '#' as URI delimiters. In applications where authorization guards inspect ctx.Path() before passing paths to file-serving handlers, double-encoded path variants (e.g., /%2561dmin/export.csv) bypass access controls while still resolving to the protected file on disk. Fixed in
1.70.0
References Updated Aug 19, 2026 · Source: OSV.dev |
v1.48.0
minor
Dependencies (7)
|
|
v1.47.0
minor
1 CVE
GO-2026-4950
Aug 18, 2026
Authorization bypass via double-encoded paths in github.com/valyala/fasthttp In github.com/valyala/fasthttp before 1.70.0, ServeFile and ServeFS reinterpret filesystem paths as URIs, decoding percent-encoded sequences and treating characters like '?' and '#' as URI delimiters. In applications where authorization guards inspect ctx.Path() before passing paths to file-serving handlers, double-encoded path variants (e.g., /%2561dmin/export.csv) bypass access controls while still resolving to the protected file on disk. Fixed in
1.70.0
References Updated Aug 19, 2026 · Source: OSV.dev |
v1.47.0
minor
Dependencies (7)
|
|
v1.44.0
minor
1 CVE
GO-2026-4950
Aug 18, 2026
Authorization bypass via double-encoded paths in github.com/valyala/fasthttp In github.com/valyala/fasthttp before 1.70.0, ServeFile and ServeFS reinterpret filesystem paths as URIs, decoding percent-encoded sequences and treating characters like '?' and '#' as URI delimiters. In applications where authorization guards inspect ctx.Path() before passing paths to file-serving handlers, double-encoded path variants (e.g., /%2561dmin/export.csv) bypass access controls while still resolving to the protected file on disk. Fixed in
1.70.0
References Updated Aug 19, 2026 · Source: OSV.dev |
v1.44.0
minor
Dependencies (7)
|
|
v1.43.0
minor
1 CVE
GO-2026-4950
Aug 18, 2026
Authorization bypass via double-encoded paths in github.com/valyala/fasthttp In github.com/valyala/fasthttp before 1.70.0, ServeFile and ServeFS reinterpret filesystem paths as URIs, decoding percent-encoded sequences and treating characters like '?' and '#' as URI delimiters. In applications where authorization guards inspect ctx.Path() before passing paths to file-serving handlers, double-encoded path variants (e.g., /%2561dmin/export.csv) bypass access controls while still resolving to the protected file on disk. Fixed in
1.70.0
References Updated Aug 19, 2026 · Source: OSV.dev |
v1.43.0
minor
Dependencies (7)
|
|
v1.41.0
minor
1 CVE
GO-2026-4950
Aug 18, 2026
Authorization bypass via double-encoded paths in github.com/valyala/fasthttp In github.com/valyala/fasthttp before 1.70.0, ServeFile and ServeFS reinterpret filesystem paths as URIs, decoding percent-encoded sequences and treating characters like '?' and '#' as URI delimiters. In applications where authorization guards inspect ctx.Path() before passing paths to file-serving handlers, double-encoded path variants (e.g., /%2561dmin/export.csv) bypass access controls while still resolving to the protected file on disk. Fixed in
1.70.0
References Updated Aug 19, 2026 · Source: OSV.dev |
v1.41.0
minor
Dependencies (7)
|
|
v1.40.0
minor
1 CVE
GO-2026-4950
Aug 18, 2026
Authorization bypass via double-encoded paths in github.com/valyala/fasthttp In github.com/valyala/fasthttp before 1.70.0, ServeFile and ServeFS reinterpret filesystem paths as URIs, decoding percent-encoded sequences and treating characters like '?' and '#' as URI delimiters. In applications where authorization guards inspect ctx.Path() before passing paths to file-serving handlers, double-encoded path variants (e.g., /%2561dmin/export.csv) bypass access controls while still resolving to the protected file on disk. Fixed in
1.70.0
References Updated Aug 19, 2026 · Source: OSV.dev |
v1.40.0
minor
Dependencies (7)
|
|
v1.38.0
minor
1 CVE
GO-2026-4950
Aug 18, 2026
Authorization bypass via double-encoded paths in github.com/valyala/fasthttp In github.com/valyala/fasthttp before 1.70.0, ServeFile and ServeFS reinterpret filesystem paths as URIs, decoding percent-encoded sequences and treating characters like '?' and '#' as URI delimiters. In applications where authorization guards inspect ctx.Path() before passing paths to file-serving handlers, double-encoded path variants (e.g., /%2561dmin/export.csv) bypass access controls while still resolving to the protected file on disk. Fixed in
1.70.0
References Updated Aug 19, 2026 · Source: OSV.dev |
v1.38.0
minor
Dependencies (7)
|
|
v1.37.0
minor
1 CVE
GO-2026-4950
Aug 18, 2026
Authorization bypass via double-encoded paths in github.com/valyala/fasthttp In github.com/valyala/fasthttp before 1.70.0, ServeFile and ServeFS reinterpret filesystem paths as URIs, decoding percent-encoded sequences and treating characters like '?' and '#' as URI delimiters. In applications where authorization guards inspect ctx.Path() before passing paths to file-serving handlers, double-encoded path variants (e.g., /%2561dmin/export.csv) bypass access controls while still resolving to the protected file on disk. Fixed in
1.70.0
References Updated Aug 19, 2026 · Source: OSV.dev |
v1.37.0
minor
Dependencies (7)
|
|
v1.36.0
minor
1 CVE
GO-2026-4950
Aug 18, 2026
Authorization bypass via double-encoded paths in github.com/valyala/fasthttp In github.com/valyala/fasthttp before 1.70.0, ServeFile and ServeFS reinterpret filesystem paths as URIs, decoding percent-encoded sequences and treating characters like '?' and '#' as URI delimiters. In applications where authorization guards inspect ctx.Path() before passing paths to file-serving handlers, double-encoded path variants (e.g., /%2561dmin/export.csv) bypass access controls while still resolving to the protected file on disk. Fixed in
1.70.0
References Updated Aug 19, 2026 · Source: OSV.dev |
v1.36.0
minor
Dependencies (7)
|
|
v1.35.0
minor
1 CVE
GO-2026-4950
Aug 18, 2026
Authorization bypass via double-encoded paths in github.com/valyala/fasthttp In github.com/valyala/fasthttp before 1.70.0, ServeFile and ServeFS reinterpret filesystem paths as URIs, decoding percent-encoded sequences and treating characters like '?' and '#' as URI delimiters. In applications where authorization guards inspect ctx.Path() before passing paths to file-serving handlers, double-encoded path variants (e.g., /%2561dmin/export.csv) bypass access controls while still resolving to the protected file on disk. Fixed in
1.70.0
References Updated Aug 19, 2026 · Source: OSV.dev |
v1.35.0
minor
Dependencies (7)
|
|
v1.32.0
minor
2 CVEs
GO-2026-4950
Aug 18, 2026
Authorization bypass via double-encoded paths in github.com/valyala/fasthttp In github.com/valyala/fasthttp before 1.70.0, ServeFile and ServeFS reinterpret filesystem paths as URIs, decoding percent-encoded sequences and treating characters like '?' and '#' as URI delimiters. In applications where authorization guards inspect ctx.Path() before passing paths to file-serving handlers, double-encoded path variants (e.g., /%2561dmin/export.csv) bypass access controls while still resolving to the protected file on disk. Fixed in
1.70.0
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2022-21221
GO-2022-0355
GHSA-fx95-883v-4q4h
SNYK-GOLANG-GITHUBCOMVALYALAFASTHTTP-2407866
Jul 27, 2022
Path traversal in github.com/valyala/fasthttp The fasthttp.FS request handler is vulnerable to directory traversal attacks on Windows systems, and can serve files from outside the provided root directory. URL path normalization does not handle Windows path separators (backslashes), permitting an attacker to construct requests with relative paths. Fixed in
1.34.0
References Updated Jul 08, 2026 · Source: OSV.dev |
v1.32.0
minor
Dependencies (7)
|
|
v1.31.0
minor
2 CVEs
GO-2026-4950
Aug 18, 2026
Authorization bypass via double-encoded paths in github.com/valyala/fasthttp In github.com/valyala/fasthttp before 1.70.0, ServeFile and ServeFS reinterpret filesystem paths as URIs, decoding percent-encoded sequences and treating characters like '?' and '#' as URI delimiters. In applications where authorization guards inspect ctx.Path() before passing paths to file-serving handlers, double-encoded path variants (e.g., /%2561dmin/export.csv) bypass access controls while still resolving to the protected file on disk. Fixed in
1.70.0
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2022-21221
GO-2022-0355
GHSA-fx95-883v-4q4h
SNYK-GOLANG-GITHUBCOMVALYALAFASTHTTP-2407866
Jul 27, 2022
Path traversal in github.com/valyala/fasthttp The fasthttp.FS request handler is vulnerable to directory traversal attacks on Windows systems, and can serve files from outside the provided root directory. URL path normalization does not handle Windows path separators (backslashes), permitting an attacker to construct requests with relative paths. Fixed in
1.34.0
References Updated Jul 08, 2026 · Source: OSV.dev |
v1.31.0
minor
Dependencies (7)
|
|
v1.29.0
minor
2 CVEs
GO-2026-4950
Aug 18, 2026
Authorization bypass via double-encoded paths in github.com/valyala/fasthttp In github.com/valyala/fasthttp before 1.70.0, ServeFile and ServeFS reinterpret filesystem paths as URIs, decoding percent-encoded sequences and treating characters like '?' and '#' as URI delimiters. In applications where authorization guards inspect ctx.Path() before passing paths to file-serving handlers, double-encoded path variants (e.g., /%2561dmin/export.csv) bypass access controls while still resolving to the protected file on disk. Fixed in
1.70.0
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2022-21221
GO-2022-0355
GHSA-fx95-883v-4q4h
SNYK-GOLANG-GITHUBCOMVALYALAFASTHTTP-2407866
Jul 27, 2022
Path traversal in github.com/valyala/fasthttp The fasthttp.FS request handler is vulnerable to directory traversal attacks on Windows systems, and can serve files from outside the provided root directory. URL path normalization does not handle Windows path separators (backslashes), permitting an attacker to construct requests with relative paths. Fixed in
1.34.0
References Updated Jul 08, 2026 · Source: OSV.dev |
v1.29.0
minor
Dependencies (7)
|
|
v1.26.0
minor
2 CVEs
GO-2026-4950
Aug 18, 2026
Authorization bypass via double-encoded paths in github.com/valyala/fasthttp In github.com/valyala/fasthttp before 1.70.0, ServeFile and ServeFS reinterpret filesystem paths as URIs, decoding percent-encoded sequences and treating characters like '?' and '#' as URI delimiters. In applications where authorization guards inspect ctx.Path() before passing paths to file-serving handlers, double-encoded path variants (e.g., /%2561dmin/export.csv) bypass access controls while still resolving to the protected file on disk. Fixed in
1.70.0
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2022-21221
GO-2022-0355
GHSA-fx95-883v-4q4h
SNYK-GOLANG-GITHUBCOMVALYALAFASTHTTP-2407866
Jul 27, 2022
Path traversal in github.com/valyala/fasthttp The fasthttp.FS request handler is vulnerable to directory traversal attacks on Windows systems, and can serve files from outside the provided root directory. URL path normalization does not handle Windows path separators (backslashes), permitting an attacker to construct requests with relative paths. Fixed in
1.34.0
References Updated Jul 08, 2026 · Source: OSV.dev |
v1.26.0
minor
Dependencies (7)
|
|
v1.25.0
minor
2 CVEs
GO-2026-4950
Aug 18, 2026
Authorization bypass via double-encoded paths in github.com/valyala/fasthttp In github.com/valyala/fasthttp before 1.70.0, ServeFile and ServeFS reinterpret filesystem paths as URIs, decoding percent-encoded sequences and treating characters like '?' and '#' as URI delimiters. In applications where authorization guards inspect ctx.Path() before passing paths to file-serving handlers, double-encoded path variants (e.g., /%2561dmin/export.csv) bypass access controls while still resolving to the protected file on disk. Fixed in
1.70.0
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2022-21221
GO-2022-0355
GHSA-fx95-883v-4q4h
SNYK-GOLANG-GITHUBCOMVALYALAFASTHTTP-2407866
Jul 27, 2022
Path traversal in github.com/valyala/fasthttp The fasthttp.FS request handler is vulnerable to directory traversal attacks on Windows systems, and can serve files from outside the provided root directory. URL path normalization does not handle Windows path separators (backslashes), permitting an attacker to construct requests with relative paths. Fixed in
1.34.0
References Updated Jul 08, 2026 · Source: OSV.dev |
v1.25.0
minor
Dependencies (7)
|
|
v1.24.0
minor
2 CVEs
GO-2026-4950
Aug 18, 2026
Authorization bypass via double-encoded paths in github.com/valyala/fasthttp In github.com/valyala/fasthttp before 1.70.0, ServeFile and ServeFS reinterpret filesystem paths as URIs, decoding percent-encoded sequences and treating characters like '?' and '#' as URI delimiters. In applications where authorization guards inspect ctx.Path() before passing paths to file-serving handlers, double-encoded path variants (e.g., /%2561dmin/export.csv) bypass access controls while still resolving to the protected file on disk. Fixed in
1.70.0
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2022-21221
GO-2022-0355
GHSA-fx95-883v-4q4h
SNYK-GOLANG-GITHUBCOMVALYALAFASTHTTP-2407866
Jul 27, 2022
Path traversal in github.com/valyala/fasthttp The fasthttp.FS request handler is vulnerable to directory traversal attacks on Windows systems, and can serve files from outside the provided root directory. URL path normalization does not handle Windows path separators (backslashes), permitting an attacker to construct requests with relative paths. Fixed in
1.34.0
References Updated Jul 08, 2026 · Source: OSV.dev |
v1.24.0
minor
Dependencies (7)
|
|
v1.23.0
minor
2 CVEs
GO-2026-4950
Aug 18, 2026
Authorization bypass via double-encoded paths in github.com/valyala/fasthttp In github.com/valyala/fasthttp before 1.70.0, ServeFile and ServeFS reinterpret filesystem paths as URIs, decoding percent-encoded sequences and treating characters like '?' and '#' as URI delimiters. In applications where authorization guards inspect ctx.Path() before passing paths to file-serving handlers, double-encoded path variants (e.g., /%2561dmin/export.csv) bypass access controls while still resolving to the protected file on disk. Fixed in
1.70.0
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2022-21221
GO-2022-0355
GHSA-fx95-883v-4q4h
SNYK-GOLANG-GITHUBCOMVALYALAFASTHTTP-2407866
Jul 27, 2022
Path traversal in github.com/valyala/fasthttp The fasthttp.FS request handler is vulnerable to directory traversal attacks on Windows systems, and can serve files from outside the provided root directory. URL path normalization does not handle Windows path separators (backslashes), permitting an attacker to construct requests with relative paths. Fixed in
1.34.0
References Updated Jul 08, 2026 · Source: OSV.dev |
v1.23.0
minor
Dependencies (7)
|
|
v1.22.0
minor
2 CVEs
GO-2026-4950
Aug 18, 2026
Authorization bypass via double-encoded paths in github.com/valyala/fasthttp In github.com/valyala/fasthttp before 1.70.0, ServeFile and ServeFS reinterpret filesystem paths as URIs, decoding percent-encoded sequences and treating characters like '?' and '#' as URI delimiters. In applications where authorization guards inspect ctx.Path() before passing paths to file-serving handlers, double-encoded path variants (e.g., /%2561dmin/export.csv) bypass access controls while still resolving to the protected file on disk. Fixed in
1.70.0
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2022-21221
GO-2022-0355
GHSA-fx95-883v-4q4h
SNYK-GOLANG-GITHUBCOMVALYALAFASTHTTP-2407866
Jul 27, 2022
Path traversal in github.com/valyala/fasthttp The fasthttp.FS request handler is vulnerable to directory traversal attacks on Windows systems, and can serve files from outside the provided root directory. URL path normalization does not handle Windows path separators (backslashes), permitting an attacker to construct requests with relative paths. Fixed in
1.34.0
References Updated Jul 08, 2026 · Source: OSV.dev |
v1.22.0
minor
Dependencies (7)
|
|
v1.21.0
minor
2 CVEs
GO-2026-4950
Aug 18, 2026
Authorization bypass via double-encoded paths in github.com/valyala/fasthttp In github.com/valyala/fasthttp before 1.70.0, ServeFile and ServeFS reinterpret filesystem paths as URIs, decoding percent-encoded sequences and treating characters like '?' and '#' as URI delimiters. In applications where authorization guards inspect ctx.Path() before passing paths to file-serving handlers, double-encoded path variants (e.g., /%2561dmin/export.csv) bypass access controls while still resolving to the protected file on disk. Fixed in
1.70.0
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2022-21221
GO-2022-0355
GHSA-fx95-883v-4q4h
SNYK-GOLANG-GITHUBCOMVALYALAFASTHTTP-2407866
Jul 27, 2022
Path traversal in github.com/valyala/fasthttp The fasthttp.FS request handler is vulnerable to directory traversal attacks on Windows systems, and can serve files from outside the provided root directory. URL path normalization does not handle Windows path separators (backslashes), permitting an attacker to construct requests with relative paths. Fixed in
1.34.0
References Updated Jul 08, 2026 · Source: OSV.dev |
v1.21.0
minor
Dependencies (7)
|
|
v1.16.0
minor
2 CVEs
GO-2026-4950
Aug 18, 2026
Authorization bypass via double-encoded paths in github.com/valyala/fasthttp In github.com/valyala/fasthttp before 1.70.0, ServeFile and ServeFS reinterpret filesystem paths as URIs, decoding percent-encoded sequences and treating characters like '?' and '#' as URI delimiters. In applications where authorization guards inspect ctx.Path() before passing paths to file-serving handlers, double-encoded path variants (e.g., /%2561dmin/export.csv) bypass access controls while still resolving to the protected file on disk. Fixed in
1.70.0
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2022-21221
GO-2022-0355
GHSA-fx95-883v-4q4h
SNYK-GOLANG-GITHUBCOMVALYALAFASTHTTP-2407866
Jul 27, 2022
Path traversal in github.com/valyala/fasthttp The fasthttp.FS request handler is vulnerable to directory traversal attacks on Windows systems, and can serve files from outside the provided root directory. URL path normalization does not handle Windows path separators (backslashes), permitting an attacker to construct requests with relative paths. Fixed in
1.34.0
References Updated Jul 08, 2026 · Source: OSV.dev |
v1.16.0
minor
Dependencies (7)
|
|
v1.15.1
patch
2 CVEs
GO-2026-4950
Aug 18, 2026
Authorization bypass via double-encoded paths in github.com/valyala/fasthttp In github.com/valyala/fasthttp before 1.70.0, ServeFile and ServeFS reinterpret filesystem paths as URIs, decoding percent-encoded sequences and treating characters like '?' and '#' as URI delimiters. In applications where authorization guards inspect ctx.Path() before passing paths to file-serving handlers, double-encoded path variants (e.g., /%2561dmin/export.csv) bypass access controls while still resolving to the protected file on disk. Fixed in
1.70.0
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2022-21221
GO-2022-0355
GHSA-fx95-883v-4q4h
SNYK-GOLANG-GITHUBCOMVALYALAFASTHTTP-2407866
Jul 27, 2022
Path traversal in github.com/valyala/fasthttp The fasthttp.FS request handler is vulnerable to directory traversal attacks on Windows systems, and can serve files from outside the provided root directory. URL path normalization does not handle Windows path separators (backslashes), permitting an attacker to construct requests with relative paths. Fixed in
1.34.0
References Updated Jul 08, 2026 · Source: OSV.dev |
v1.15.1
patch
Dependencies (7)
|
|
v1.15.0
minor
2 CVEs
GO-2026-4950
Aug 18, 2026
Authorization bypass via double-encoded paths in github.com/valyala/fasthttp In github.com/valyala/fasthttp before 1.70.0, ServeFile and ServeFS reinterpret filesystem paths as URIs, decoding percent-encoded sequences and treating characters like '?' and '#' as URI delimiters. In applications where authorization guards inspect ctx.Path() before passing paths to file-serving handlers, double-encoded path variants (e.g., /%2561dmin/export.csv) bypass access controls while still resolving to the protected file on disk. Fixed in
1.70.0
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2022-21221
GO-2022-0355
GHSA-fx95-883v-4q4h
SNYK-GOLANG-GITHUBCOMVALYALAFASTHTTP-2407866
Jul 27, 2022
Path traversal in github.com/valyala/fasthttp The fasthttp.FS request handler is vulnerable to directory traversal attacks on Windows systems, and can serve files from outside the provided root directory. URL path normalization does not handle Windows path separators (backslashes), permitting an attacker to construct requests with relative paths. Fixed in
1.34.0
References Updated Jul 08, 2026 · Source: OSV.dev |
v1.15.0
minor
Dependencies (7)
|
|
v1.13.0
minor
2 CVEs
GO-2026-4950
Aug 18, 2026
Authorization bypass via double-encoded paths in github.com/valyala/fasthttp In github.com/valyala/fasthttp before 1.70.0, ServeFile and ServeFS reinterpret filesystem paths as URIs, decoding percent-encoded sequences and treating characters like '?' and '#' as URI delimiters. In applications where authorization guards inspect ctx.Path() before passing paths to file-serving handlers, double-encoded path variants (e.g., /%2561dmin/export.csv) bypass access controls while still resolving to the protected file on disk. Fixed in
1.70.0
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2022-21221
GO-2022-0355
GHSA-fx95-883v-4q4h
SNYK-GOLANG-GITHUBCOMVALYALAFASTHTTP-2407866
Jul 27, 2022
Path traversal in github.com/valyala/fasthttp The fasthttp.FS request handler is vulnerable to directory traversal attacks on Windows systems, and can serve files from outside the provided root directory. URL path normalization does not handle Windows path separators (backslashes), permitting an attacker to construct requests with relative paths. Fixed in
1.34.0
References Updated Jul 08, 2026 · Source: OSV.dev |
v1.13.0
minor
Dependencies (5)
|
|
v0.1.0
initial
2 CVEs
GO-2026-4950
Aug 18, 2026
Authorization bypass via double-encoded paths in github.com/valyala/fasthttp In github.com/valyala/fasthttp before 1.70.0, ServeFile and ServeFS reinterpret filesystem paths as URIs, decoding percent-encoded sequences and treating characters like '?' and '#' as URI delimiters. In applications where authorization guards inspect ctx.Path() before passing paths to file-serving handlers, double-encoded path variants (e.g., /%2561dmin/export.csv) bypass access controls while still resolving to the protected file on disk. Fixed in
1.70.0
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2022-21221
GO-2022-0355
GHSA-fx95-883v-4q4h
SNYK-GOLANG-GITHUBCOMVALYALAFASTHTTP-2407866
Jul 27, 2022
Path traversal in github.com/valyala/fasthttp The fasthttp.FS request handler is vulnerable to directory traversal attacks on Windows systems, and can serve files from outside the provided root directory. URL path normalization does not handle Windows path separators (backslashes), permitting an attacker to construct requests with relative paths. Fixed in
1.34.0
References Updated Jul 08, 2026 · Source: OSV.dev |
v0.1.0
initial
Dependencies (3)
|
|
v1.11.0
minor
2 CVEs
GO-2026-4950
Aug 18, 2026
Authorization bypass via double-encoded paths in github.com/valyala/fasthttp In github.com/valyala/fasthttp before 1.70.0, ServeFile and ServeFS reinterpret filesystem paths as URIs, decoding percent-encoded sequences and treating characters like '?' and '#' as URI delimiters. In applications where authorization guards inspect ctx.Path() before passing paths to file-serving handlers, double-encoded path variants (e.g., /%2561dmin/export.csv) bypass access controls while still resolving to the protected file on disk. Fixed in
1.70.0
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2022-21221
GO-2022-0355
GHSA-fx95-883v-4q4h
SNYK-GOLANG-GITHUBCOMVALYALAFASTHTTP-2407866
Jul 27, 2022
Path traversal in github.com/valyala/fasthttp The fasthttp.FS request handler is vulnerable to directory traversal attacks on Windows systems, and can serve files from outside the provided root directory. URL path normalization does not handle Windows path separators (backslashes), permitting an attacker to construct requests with relative paths. Fixed in
1.34.0
References Updated Jul 08, 2026 · Source: OSV.dev |
v1.11.0
minor
Dependencies (4)
|