Fiber
Vendor:
First CVE: Jul 20, 2020 · Active for 6 years
17
Total CVEs
More Total CVEs than 93% of tracked products
3.4
Avg CVEs / Year
Higher CVE frequency than 82% of tracked products
7.2
Avg CVSS
Higher Avg CVSS than 45% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Fiber over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 20, 2020
6 years ago
Most Recent CVE
Jul 8, 2026
18 days ago
CVE Severity & Scoring
Fiber17 CVEs
41%
41%
18%
All CVEs352,719 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network17 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low16 (94.1%)
High1 (5.9%)
Unknown0 (0.0%)
User Interaction
None13 (76.5%)
Unknown0 (0.0%)
Required4 (23.5%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None17 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-66630CRITICAL Fiber is an Express inspired web framework written in Go. Before 2.52.11, on Go versions prior to 1.24, the underlying crypto/rand implementation can return an error if secure rand | Feb 9, 2026 | 9.4 | 31 | NO | NO |
CVE-2024-38513CRITICAL Fiber is an Express-inspired web framework written in Go A vulnerability present in versions prior to 2.52.5 is a session middleware issue in GoFiber versions 2 and above. This vul | Jul 1, 2024 | 9.8 | 30 | NO | NO |
CVE-2024-25124CRITICAL Fiber is a web framework written in go. Prior to version 2.52.1, the CORS middleware allows for insecure configurations that could potentially expose the application to multiple CO | Feb 21, 2024 | 9.8 | 28 | NO | NO |
CVE-2026-25891HIGH Fiber is an Express inspired web framework written in Go. A Path Traversal (CWE-22) vulnerability in Fiber allows a remote attacker to bypass the static middleware sanitizer and re | Feb 24, 2026 | 7.5 | 27 | NO | NO |
CVE-2026-30246MEDIUM Fiber is a web framework for Go. In github.com/gofiber/fiber/v3 versions through 3.1.0, the default key generator in the cache middleware uses only the request path and does not in | May 5, 2026 | 6.5 | 26 | NO | NO |
CVE-2026-25899HIGH Fiber is an Express inspired web framework written in Go. In versions on the v3 branch prior to 3.1.0, the use of the `fiber_flash` cookie can force an unbounded allocation on any | Feb 24, 2026 | 7.5 | 26 | NO | NO |
CVE-2026-25882HIGH Fiber is an Express inspired web framework written in Go. A denial of service vulnerability exists in Fiber v2 and v3 that allows remote attackers to crash the application by sendi | Feb 24, 2026 | 7.5 | 26 | NO | NO |
CVE-2023-45141HIGH Fiber is an express inspired web framework written in Go. A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the application, which allows an attacker to obta | Oct 16, 2023 | 8.8 | 26 | NO | NO |
CVE-2023-45128HIGH Fiber is an express inspired web framework written in Go. A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the application, which allows an attacker to inje | Oct 16, 2023 | 8.8 | 26 | NO | NO |
CVE-2026-44332MEDIUM Fiber is an Express inspired web framework written in Go. Prior to 3.3.0, the default Authorizer function in the BasicAuth middleware in middleware/basicauth/config.go uses short-c | Jul 8, 2026 | 5.3 | 25 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (17 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (17 CVEs).
Media Mentions
Signals from CVEs in this product scope (17 CVEs).
Top CNAs Publishing CVEs For Fiber
Top CWEs
Versions
No cataloged versions.