Gofiber is a modestly represented web framework vendor whose vulnerability footprint centers on a small number of products including Fiber, Django, and utilities packages that serve application-layer use cases. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated tendency toward critical severity, and recur through classic web-application weakness classes including cross-site request forgery, improper input validation, cross-site scripting, array-index validation, and memory allocation issues that reflect parser and request-handling complexity. Defenders should monitor this vendor's releases for application-tier exposure and treat framework-level flaws as broadly applicable to dependent applications; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gofiber over time
Signals from CVEs in this vendor scope (19 CVEs).
19 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-66630CRITICAL Fiber is an Express inspired web framework written in Go. Before 2.52.11, on Go versions prior to 1.24, the underlying crypto/rand implementation can return an error if secure rand | Feb 9, 2026 | 9.4 | 31 | NO | NO |
CVE-2025-66565CRITICAL Fiber Utils is a collection of common functions created for Fiber. In versions 2.0.0-rc.3 and below, when the system's cryptographic random number generator (crypto/rand) fails, bo | Dec 9, 2025 | 9.8 | 31 | NO | NO |
CVE-2024-38513CRITICAL Fiber is an Express-inspired web framework written in Go A vulnerability present in versions prior to 2.52.5 is a session middleware issue in GoFiber versions 2 and above. This vul | Jul 1, 2024 | 9.8 | 30 | NO | NO |
CVE-2024-25124CRITICAL Fiber is a web framework written in go. Prior to version 2.52.1, the CORS middleware allows for insecure configurations that could potentially expose the application to multiple CO | Feb 21, 2024 | 9.8 | 28 | NO | NO |
CVE-2026-25891HIGH Fiber is an Express inspired web framework written in Go. A Path Traversal (CWE-22) vulnerability in Fiber allows a remote attacker to bypass the static middleware sanitizer and re | Feb 24, 2026 | 7.5 | 27 | NO | NO |
CVE-2026-30246MEDIUM Fiber is a web framework for Go. In github.com/gofiber/fiber/v3 versions through 3.1.0, the default key generator in the cache middleware uses only the request path and does not in | May 5, 2026 | 6.5 | 26 | NO | NO |
CVE-2026-25899HIGH Fiber is an Express inspired web framework written in Go. In versions on the v3 branch prior to 3.1.0, the use of the `fiber_flash` cookie can force an unbounded allocation on any | Feb 24, 2026 | 7.5 | 26 | NO | NO |
CVE-2026-25882HIGH Fiber is an Express inspired web framework written in Go. A denial of service vulnerability exists in Fiber v2 and v3 that allows remote attackers to crash the application by sendi | Feb 24, 2026 | 7.5 | 26 | NO | NO |
CVE-2023-45141HIGH Fiber is an express inspired web framework written in Go. A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the application, which allows an attacker to obta | Oct 16, 2023 | 8.8 | 26 | NO | NO |
CVE-2023-45128HIGH Fiber is an express inspired web framework written in Go. A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the application, which allows an attacker to inje | Oct 16, 2023 | 8.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (19 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gofiber.
Media articles that mention a CVE ID that affects a product developed by Gofiber — matched by CVE ID, not by vendor name.