Package impact

golang Go / github.com/gofiber/fiber/v2

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-42554 medium 6.1 6.1 23d ago Fiber vulnerable to XSS in AutoFormat Content Negotiation
CVE-2026-25882 unknown 3mo ago Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber
CVE-2025-66630 unknown 4mo ago Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() on crypto/rand failure in github.com/gofiber/fiber
CVE-2025-54801 unknown 10mo ago Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder in github.com/gofiber/fiber
CVE-2025-48075 unknown 1y ago Fiber panics when fiber.Ctx.BodyParser parses invalid range index in github.com/gofiber/fiber
CVE-2024-38513 unknown 2y ago Session Middleware Token Injection Vulnerability in github.com/gofiber/fiber
CVE-2024-25124 unknown 2y ago Insecure CORS Configuration allowing wildcard origin with credentials in github.com/gofiber/fiber/v2
CVE-2023-45141 unknown 3y ago CSRF token validation vulnerability in github.com/gofiber/fiber/v2
CVE-2023-45128 unknown 3y ago CSRF token reuse vulnerability in github.com/gofiber/fiber/v2
CVE-2023-41338 unknown 3y ago IsFromLocal local address check can be circumvented in github.com/gofiber/fiber/v2
CVE-2018-20744 unknown 4y ago Insecure wildcard CORS policy in github.com/rs/cors