CVE-2026-25891 is a Path Traversal vulnerability (CWE-22) affecting Fiber v3 versions up to 3.0.0, a Go-based web framework. This flaw allows a remote attacker to bypass the static middleware sanitizer on Windows systems, enabling the unauthorized reading of arbitrary files. The vulnerability carries a CVSS score of 7.5 (HIGH), indicating a network-exploitable, low-complexity attack with high confidentiality impact. There is currently no public exploit code available (Metasploit, Nuclei, ExploitDB), and it is not listed in the KEV catalog, though it has garnered some community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.0.0, < 3.1.0CPE matchmatch criteria | cpe:2.3:a:gofiber:fiber:*:*:*:*:*:go:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.