CVE-2026-25882 is a denial-of-service vulnerability affecting Fiber, an Express-inspired Go web framework, specifically in versions v2 and v3. Remote attackers can crash applications by sending requests to routes with over 30 parameters due to missing validation and unbounded array writes during request matching. This vulnerability carries a CVSS score of 7.5 (HIGH), indicating a network-attackable, low-complexity exploit with high impact on availability. There is currently no evidence of active exploitation, nor are there public exploits available in Metasploit, Nuclei, or ExploitDB. However, the vulnerability has garnered some community discussion and media coverage, suggesting awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.0.0, < 2.52.12CPE matchmatch criteria | cpe:2.3:a:gofiber:fiber:*:*:*:*:*:go:*:* | ||
>= 3.0.0, < 3.1.0CPE matchmatch criteria | cpe:2.3:a:gofiber:fiber:*:*:*:*:*:go:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.