Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Gofiber

First CVE: Jul 20, 2020Active for: 6 yearsTotal CVEs: 19
35.8
VTI Score
Medium

Gofiber is a modestly represented web framework vendor whose vulnerability footprint centers on a small number of products including Fiber, Django, and utilities packages that serve application-layer use cases. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated tendency toward critical severity, and recur through classic web-application weakness classes including cross-site request forgery, improper input validation, cross-site scripting, array-index validation, and memory allocation issues that reflect parser and request-handling complexity. Defenders should monitor this vendor's releases for application-tier exposure and treat framework-level flaws as broadly applicable to dependent applications; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
19
Total CVEs
More Total CVEs than 96% of tracked vendors
1.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 75% of tracked vendors
7.3
Avg CVSS Score
Higher Avg CVSS Score than 55% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Gofiber over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 20, 2020
6 years ago
Most Recent CVE
Jul 8, 2026
16 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (19 CVEs).

19 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-66630CRITICAL
Fiber is an Express inspired web framework written in Go. Before 2.52.11, on Go versions prior to 1.24, the underlying crypto/rand implementation can return an error if secure rand
Feb 9, 20269.431NONO
CVE-2025-66565CRITICAL
Fiber Utils is a collection of common functions created for Fiber. In versions 2.0.0-rc.3 and below, when the system's cryptographic random number generator (crypto/rand) fails, bo
Dec 9, 20259.831NONO
CVE-2024-38513CRITICAL
Fiber is an Express-inspired web framework written in Go A vulnerability present in versions prior to 2.52.5 is a session middleware issue in GoFiber versions 2 and above. This vul
Jul 1, 20249.830NONO
CVE-2024-25124CRITICAL
Fiber is a web framework written in go. Prior to version 2.52.1, the CORS middleware allows for insecure configurations that could potentially expose the application to multiple CO
Feb 21, 20249.828NONO
CVE-2026-25891HIGH
Fiber is an Express inspired web framework written in Go. A Path Traversal (CWE-22) vulnerability in Fiber allows a remote attacker to bypass the static middleware sanitizer and re
Feb 24, 20267.527NONO
CVE-2026-30246MEDIUM
Fiber is a web framework for Go. In github.com/gofiber/fiber/v3 versions through 3.1.0, the default key generator in the cache middleware uses only the request path and does not in
May 5, 20266.526NONO
CVE-2026-25899HIGH
Fiber is an Express inspired web framework written in Go. In versions on the v3 branch prior to 3.1.0, the use of the `fiber_flash` cookie can force an unbounded allocation on any
Feb 24, 20267.526NONO
CVE-2026-25882HIGH
Fiber is an Express inspired web framework written in Go. A denial of service vulnerability exists in Fiber v2 and v3 that allows remote attackers to crash the application by sendi
Feb 24, 20267.526NONO
CVE-2023-45141HIGH
Fiber is an express inspired web framework written in Go. A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the application, which allows an attacker to obta
Oct 16, 20238.826NONO
CVE-2023-45128HIGH
Fiber is an express inspired web framework written in Go. A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the application, which allows an attacker to inje
Oct 16, 20238.826NONO
View all 19 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products19 CVEs
42%
37%
21%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network19 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low18 (94.7%)
High1 (5.3%)
Unknown0 (0.0%)
User Interaction
None14 (73.7%)
Unknown0 (0.0%)
Required5 (26.3%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None19 (100.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (19 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Gofiber.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Gofiber — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Gofiber's Products

View all 1 CNAs →

Top CWEs