{"schema_version":1,"title":"github.com/gofiber/fiber/v3 (Go) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 8 vulnerabilities in github.com/gofiber/fiber/v3 (Go): 0 in the last 7 days and 3 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-53624, was published on 8 July 2026.","url":"https://junglewise.ai/threats/technologies/github-com-gofiber-fiber-v3","json_url":"https://junglewise.ai/threats/technologies/github-com-gofiber-fiber-v3.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/github-com-gofiber-fiber-v3","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":0,"all_time":8,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":3,"last_365_days":8},"latest":[{"cve":"CVE-2026-53624","cvss":4.8,"epss":0.0021,"slug":"cve-2026-53624-gofiber-fiber-hsts-header-omission-in-helmet-middleware","title":"Gofiber Fiber HSTS header omission in helmet middleware","severity":"medium","exploited":false,"published_at":"2026-07-08T20:16:52.293+00:00","url":"https://junglewise.ai/threats/cve-2026-53624-gofiber-fiber-hsts-header-omission-in-helmet-middleware"},{"cve":"CVE-2026-45045","cvss":5.3,"epss":0.0046,"slug":"cve-2026-45045-gofiber-fiber-ip-spoofing-in-balancerforward-proxy-helper","title":"Gofiber Fiber IP spoofing in BalancerForward proxy helper","severity":"medium","exploited":false,"published_at":"2026-07-08T20:16:50.06+00:00","url":"https://junglewise.ai/threats/cve-2026-45045-gofiber-fiber-ip-spoofing-in-balancerforward-proxy-helper"},{"cve":"CVE-2026-44332","cvss":5.3,"epss":0.0052,"slug":"cve-2026-44332-gofiber-fiber-username-enumeration-in-basicauth-middleware","title":"Gofiber Fiber username enumeration in BasicAuth middleware","severity":"medium","exploited":false,"published_at":"2026-07-08T20:16:49.773+00:00","url":"https://junglewise.ai/threats/cve-2026-44332-gofiber-fiber-username-enumeration-in-basicauth-middleware"},{"cve":"CVE-2026-42554","cvss":4,"epss":0.0031,"slug":"cve-2026-42554-go-fiber-xss-in-autoformat-content-negotiation","title":"Go Fiber XSS in AutoFormat content negotiation","severity":"medium","exploited":false,"published_at":"2026-05-11T23:19:48.083+00:00","url":"https://junglewise.ai/threats/cve-2026-42554-go-fiber-xss-in-autoformat-content-negotiation"},{"cve":"CVE-2026-30246","cvss":6.5,"epss":0.0037,"slug":"cve-2026-30246-gofiber-fiber-response-mix-up-in-cache-middleware","title":"Gofiber Fiber response mix-up in cache middleware","severity":"medium","exploited":false,"published_at":"2026-05-05T13:16:28.82+00:00","url":"https://junglewise.ai/threats/cve-2026-30246-gofiber-fiber-response-mix-up-in-cache-middleware"},{"cve":"CVE-2026-25891","cvss":4,"epss":0.0069,"slug":"cve-2026-25891-fiber-has-an-arbitrary-file-read-in-static-middleware-on-windows","title":"GO-2026-4540 - Fiber has an Arbitrary File Read in Static Middleware on Windows in github.com/gofiber/fiber/v3","severity":"medium","exploited":false,"published_at":"2026-02-26T16:27:51+00:00","url":"https://junglewise.ai/threats/cve-2026-25891-fiber-has-an-arbitrary-file-read-in-static-middleware-on-windows"},{"cve":"CVE-2026-25882","cvss":4,"epss":0.0081,"slug":"cve-2026-25882-fiber-has-a-denial-of-service-vulnerability-via-route-parameter","title":"GO-2026-4543 - Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber","severity":"medium","exploited":false,"published_at":"2026-02-26T16:27:51+00:00","url":"https://junglewise.ai/threats/cve-2026-25882-fiber-has-a-denial-of-service-vulnerability-via-route-parameter"},{"cve":"CVE-2026-25899","cvss":3.1,"epss":0.0063,"slug":"cve-2026-25899-fiber-is-vulnerable-to-denial-of-service-via-flash-cookie","title":"GO-2026-4534 - Fiber is Vulnerable to Denial of Service via Flash Cookie Unbounded Allocation in github.com/gofiber/fiber/v3","severity":"low","exploited":false,"published_at":"2026-02-26T16:27:51+00:00","url":"https://junglewise.ai/threats/cve-2026-25899-fiber-is-vulnerable-to-denial-of-service-via-flash-cookie"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"github.com/siyuan-note/siyuan/kernel (Go)","slug":"github-com-siyuan-note-siyuan-kernel","vulnerabilities":83,"url":"https://junglewise.ai/threats/technologies/github-com-siyuan-note-siyuan-kernel"},{"name":"code.gitea.io/gitea (Go)","slug":"code-gitea-io-gitea","vulnerabilities":76,"url":"https://junglewise.ai/threats/technologies/code-gitea-io-gitea"},{"name":"github.com/rclone/rclone (Go)","slug":"github-com-rclone-rclone","vulnerabilities":26,"url":"https://junglewise.ai/threats/technologies/github-com-rclone-rclone"},{"name":"gogs.io/gogs (Go)","slug":"gogs-io-gogs","vulnerabilities":25,"url":"https://junglewise.ai/threats/technologies/gogs-io-gogs"},{"name":"github.com/filebrowser/filebrowser/v2 (Go)","slug":"github-com-filebrowser-filebrowser-v2","vulnerabilities":18,"url":"https://junglewise.ai/threats/technologies/github-com-filebrowser-filebrowser-v2"},{"name":"github.com/fission/fission (Go)","slug":"github-com-fission-fission","vulnerabilities":18,"url":"https://junglewise.ai/threats/technologies/github-com-fission-fission"},{"name":"github.com/klever-io/klever-go (Go)","slug":"github-com-klever-io-klever-go","vulnerabilities":18,"url":"https://junglewise.ai/threats/technologies/github-com-klever-io-klever-go"},{"name":"code.vikunja.io/api (Go)","slug":"code-vikunja-io-api","vulnerabilities":15,"url":"https://junglewise.ai/threats/technologies/code-vikunja-io-api"},{"name":"github.com/cloudreve/Cloudreve/v4 (Go)","slug":"github-com-cloudreve-cloudreve-v4","vulnerabilities":15,"url":"https://junglewise.ai/threats/technologies/github-com-cloudreve-cloudreve-v4"},{"name":"github.com/gotenberg/gotenberg/v8 (Go)","slug":"github-com-gotenberg-gotenberg-v8","vulnerabilities":14,"url":"https://junglewise.ai/threats/technologies/github-com-gotenberg-gotenberg-v8"},{"name":"github.com/nezhahq/nezha (Go)","slug":"github-com-nezhahq-nezha","vulnerabilities":14,"url":"https://junglewise.ai/threats/technologies/github-com-nezhahq-nezha"},{"name":"github.com/fleetdm/fleet/v4 (Go)","slug":"github-com-fleetdm-fleet-v4","vulnerabilities":13,"url":"https://junglewise.ai/threats/technologies/github-com-fleetdm-fleet-v4"}],"technology":{"hub":true,"name":"github.com/gofiber/fiber/v3 (Go)","slug":"github-com-gofiber-fiber-v3","vendor":{"name":"Go","slug":"go","url":"https://junglewise.ai/threats/vendors/go"},"aliases":[],"homepage":"https://gofiber.io/","repo_url":"https://github.com/gofiber/fiber","description":"Version 3 of the Fiber web framework, an Express-inspired framework for the Go programming language.","url":"https://junglewise.ai/threats/technologies/github-com-gofiber-fiber-v3"},"most_severe":[{"cve":"CVE-2026-30246","cvss":6.5,"epss":0.0037,"slug":"cve-2026-30246-gofiber-fiber-response-mix-up-in-cache-middleware","title":"Gofiber Fiber response mix-up in cache middleware","severity":"medium","exploited":false,"published_at":"2026-05-05T13:16:28.82+00:00","url":"https://junglewise.ai/threats/cve-2026-30246-gofiber-fiber-response-mix-up-in-cache-middleware"},{"cve":"CVE-2026-44332","cvss":5.3,"epss":0.0052,"slug":"cve-2026-44332-gofiber-fiber-username-enumeration-in-basicauth-middleware","title":"Gofiber Fiber username enumeration in BasicAuth middleware","severity":"medium","exploited":false,"published_at":"2026-07-08T20:16:49.773+00:00","url":"https://junglewise.ai/threats/cve-2026-44332-gofiber-fiber-username-enumeration-in-basicauth-middleware"},{"cve":"CVE-2026-45045","cvss":5.3,"epss":0.0046,"slug":"cve-2026-45045-gofiber-fiber-ip-spoofing-in-balancerforward-proxy-helper","title":"Gofiber Fiber IP spoofing in BalancerForward proxy helper","severity":"medium","exploited":false,"published_at":"2026-07-08T20:16:50.06+00:00","url":"https://junglewise.ai/threats/cve-2026-45045-gofiber-fiber-ip-spoofing-in-balancerforward-proxy-helper"},{"cve":"CVE-2026-53624","cvss":4.8,"epss":0.0021,"slug":"cve-2026-53624-gofiber-fiber-hsts-header-omission-in-helmet-middleware","title":"Gofiber Fiber HSTS header omission in helmet middleware","severity":"medium","exploited":false,"published_at":"2026-07-08T20:16:52.293+00:00","url":"https://junglewise.ai/threats/cve-2026-53624-gofiber-fiber-hsts-header-omission-in-helmet-middleware"},{"cve":"CVE-2026-25882","cvss":4,"epss":0.0081,"slug":"cve-2026-25882-fiber-has-a-denial-of-service-vulnerability-via-route-parameter","title":"GO-2026-4543 - Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber","severity":"medium","exploited":false,"published_at":"2026-02-26T16:27:51+00:00","url":"https://junglewise.ai/threats/cve-2026-25882-fiber-has-a-denial-of-service-vulnerability-via-route-parameter"},{"cve":"CVE-2026-25891","cvss":4,"epss":0.0069,"slug":"cve-2026-25891-fiber-has-an-arbitrary-file-read-in-static-middleware-on-windows","title":"GO-2026-4540 - Fiber has an Arbitrary File Read in Static Middleware on Windows in github.com/gofiber/fiber/v3","severity":"medium","exploited":false,"published_at":"2026-02-26T16:27:51+00:00","url":"https://junglewise.ai/threats/cve-2026-25891-fiber-has-an-arbitrary-file-read-in-static-middleware-on-windows"},{"cve":"CVE-2026-42554","cvss":4,"epss":0.0031,"slug":"cve-2026-42554-go-fiber-xss-in-autoformat-content-negotiation","title":"Go Fiber XSS in AutoFormat content negotiation","severity":"medium","exploited":false,"published_at":"2026-05-11T23:19:48.083+00:00","url":"https://junglewise.ai/threats/cve-2026-42554-go-fiber-xss-in-autoformat-content-negotiation"},{"cve":"CVE-2026-25899","cvss":3.1,"epss":0.0063,"slug":"cve-2026-25899-fiber-is-vulnerable-to-denial-of-service-via-flash-cookie","title":"GO-2026-4534 - Fiber is Vulnerable to Denial of Service via Flash Cookie Unbounded Allocation in github.com/gofiber/fiber/v3","severity":"low","exploited":false,"published_at":"2026-02-26T16:27:51+00:00","url":"https://junglewise.ai/threats/cve-2026-25899-fiber-is-vulnerable-to-denial-of-service-via-flash-cookie"}],"generated_at":"2026-09-26T16:07:00.132667+00:00"}