CVE-2026-25891

Fiber is an Express inspired web framework written in Go. A Path Traversal (CWE-22) vulnerability in Fiber allows a remote attacker to bypass the static middleware sanitizer and read arbitrary files on the server file system on Windows. This affects Fiber v3 through version 3.0.0. This has been patched in Fiber v3 version 3.1.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:gofiber:fiber:*:*:*:*:*:go:*:*

History

27 Feb 2026, 03:18

Type Values Removed Values Added
References () https://github.com/gofiber/fiber/commit/59133702301c2ab7b776dd123b474cbd995f2c86 - () https://github.com/gofiber/fiber/commit/59133702301c2ab7b776dd123b474cbd995f2c86 - Patch
References () https://github.com/gofiber/fiber/pull/4064 - () https://github.com/gofiber/fiber/pull/4064 - Exploit, Issue Tracking
References () https://github.com/gofiber/fiber/security/advisories/GHSA-m3c2-496v-cw3v - () https://github.com/gofiber/fiber/security/advisories/GHSA-m3c2-496v-cw3v - Exploit, Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
First Time Gofiber
Gofiber fiber
CPE cpe:2.3:a:gofiber:fiber:*:*:*:*:*:go:*:*

24 Feb 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-24 22:16

Updated : 2026-02-27 03:18


NVD link : CVE-2026-25891

Mitre link : CVE-2026-25891

CVE.ORG link : CVE-2026-25891


JSON object : View

Products Affected

gofiber

  • fiber
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')