Executive brief
Fiber has an Arbitrary File Read in Static Middleware on Windows in github.com/gofiber/fiber/v3
Affected products
- Go github.com/gofiber/fiber/v3
Junglewise Threat Intelligence
CVE-2026-25891 · Severity: medium · CVSS 4 · Published 2026-02-26
Technologies: github.com/gofiber/fiber/v3 (Go). Vendors: Go.
Fiber has an Arbitrary File Read in Static Middleware on Windows in github.com/gofiber/fiber/v3