Vulnerability index

Browse CVEs

18 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fiber MEDIUM 5.3
CVE-2026-45045

Fiber is an Express inspired web framework written in Go. Prior to 3.3.0 and 2.52.14, the BalancerForward proxy helper in middleware/proxy/proxy.go u…

Fix: 2.52.14 / 3.3.0+
Fix from $1,600 2026-07-08
Fiber MEDIUM 5.3
CVE-2026-44332

Fiber is an Express inspired web framework written in Go. Prior to 3.3.0, the default Authorizer function in the BasicAuth middleware in middleware/b…

Fix: 3.3.0+
Fix from $1,600 2026-07-08
Fiber MEDIUM 6.1
CVE-2026-42554

Fiber is a web framework for Go. Prior to 2.52.12 and 3.1.0, Cross-Site Scripting vulnerability in Go Fiber allows a remote attacker to inject arbitr…

Fix: 2.52.12 / 3.1.0+
Fix from $1,600 2026-05-11
Fiber MEDIUM 6.5
CVE-2026-30246

Fiber is a web framework for Go. In github.com/gofiber/fiber/v3 versions through 3.1.0, the default key generator in the cache middleware uses only t…

Fix: after 3.1.0
Fix from $1,600 2026-05-05
Fiber HIGH 7.5
CVE-2026-25891

Fiber is an Express inspired web framework written in Go. A Path Traversal (CWE-22) vulnerability in Fiber allows a remote attacker to bypass the sta…

Fix: 3.1.0+
Fix from $1,950 2026-02-24
Fiber HIGH 7.5
CVE-2026-25899

Fiber is an Express inspired web framework written in Go. In versions on the v3 branch prior to 3.1.0, the use of the `fiber_flash` cookie can force …

Fix: 3.1.0+
Fix from $1,950 2026-02-24
Fiber HIGH 7.5
CVE-2026-25882

Fiber is an Express inspired web framework written in Go. A denial of service vulnerability exists in Fiber v2 and v3 that allows remote attackers to…

Fix: 2.52.12 / 3.1.0+
Fix from $1,950 2026-02-24
Fiber CRITICAL 9.4
CVE-2025-66630

Fiber is an Express inspired web framework written in Go. Before 2.52.11, on Go versions prior to 1.24, the underlying crypto/rand implementation can…

Fix: 2.52.11+
Fix from $2,300 2026-02-09
Utils CRITICAL 9.8
CVE-2025-66565

Fiber Utils is a collection of common functions created for Fiber. In versions 2.0.0-rc.3 and below, when the system's cryptographic random number ge…

Fix: after 1.2.0
Fix from $2,300 2025-12-09
Fiber HIGH 7.5
CVE-2025-54801

Fiber is an Express inspired web framework written in Go. In versions 2.52.8 and below, when using Fiber's Ctx.BodyParser to parse form data containi…

Fix: 2.52.9+
Fix from $1,950 2025-08-06
Fiber HIGH 7.5
CVE-2025-48075

Fiber is an Express-inspired web framework written in Go. Starting in version 2.52.6 and prior to version 2.52.7, `fiber.Ctx.BodyParser` can map flat…

Fix: 2.52.7+
Fix from $1,950 2025-05-22
Fiber CRITICAL 9.8
CVE-2024-38513

Fiber is an Express-inspired web framework written in Go A vulnerability present in versions prior to 2.52.5 is a session middleware issue in GoFiber…

Fix: 2.52.5+
Fix from $2,300 2024-07-01
Fiber CRITICAL 9.8
CVE-2024-25124

Fiber is a web framework written in go. Prior to version 2.52.1, the CORS middleware allows for insecure configurations that could potentially expose…

Fix: 2.52.1+
Fix from $2,300 2024-02-21
Django MEDIUM 6.1
CVE-2024-22199

This package provides universal methods to use multiple template engines with the Fiber web framework using the Views interface. This vulnerability s…

Fix: 3.1.9+
Fix from $1,600 2024-01-11
Fiber HIGH 8.8
CVE-2023-45128

Fiber is an express inspired web framework written in Go. A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the application, w…

Fix: 2.50.0+
Fix from $1,950 2023-10-16
Fiber HIGH 8.8
CVE-2023-45141

Fiber is an express inspired web framework written in Go. A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the application, w…

Fix: 2.50.0+
Fix from $1,950 2023-10-16
Fiber MEDIUM 5.3
CVE-2023-41338

Fiber is an Express inspired web framework built in the go language. Versions of gofiber prior to 2.49.2 did not properly restrict access to localhos…

Fix: 2.49.2+
Fix from $1,600 2023-09-08
Fiber MEDIUM 5.4
CVE-2020-15111

In Fiber before version 1.12.6, the filename that is given in c.Attachment() (https://docs.gofiber.io/ctx#attachment) is not escaped, and therefore v…

Fix: 1.12.6+
Fix from $1,600 2020-07-20