CVE-2026-25899 is a critical vulnerability affecting GoFiber v3 web frameworks prior to version 3.1.0, where an unauthenticated attacker can trigger an unbounded memory allocation by sending a crafted fiber_flash cookie. This vulnerability has a CVSS score of 7.5 (High) due to its network-based attack vector, low complexity, and potential for denial-of-service (DoS) by consuming up to 85GB of memory. While there is no evidence of active exploitation, nor publicly available exploit code, the vulnerability has garnered some community discussion and media coverage. Organizations using affected GoFiber versions should prioritize upgrading to version 3.1.0 to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.0.0, < 3.1.0CPE matchmatch criteria | cpe:2.3:a:gofiber:fiber:*:*:*:*:*:go:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.