CVE-2026-25891

Fiber is an Express inspired web framework written in Go. A Path Traversal (CWE-22) vulnerability in Fiber allows a remote attacker to bypass the static middleware sanitizer and read arbitrary files on the server file system on Windows. This affects Fiber v3 through version 3.0.0. This has been patched in Fiber v3 version 3.1.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:gofiber:fiber:*:*:*:*:*:go:*:*

History

17 Jun 2026, 10:25

Type Values Removed Values Added
Summary
  • (es) Fiber es un framework web inspirado en Express escrito en Go. Una vulnerabilidad de salto de ruta (CWE-22) en Fiber permite a un atacante remoto eludir el saneador del middleware estático y leer archivos arbitrarios en el sistema de archivos del servidor en Windows. Esto afecta a Fiber v3 hasta la versión 3.0.0. Esto ha sido parcheado en Fiber v3 versión 3.1.0.

27 Feb 2026, 03:18

Type Values Removed Values Added
References () https://github.com/gofiber/fiber/commit/59133702301c2ab7b776dd123b474cbd995f2c86 - () https://github.com/gofiber/fiber/commit/59133702301c2ab7b776dd123b474cbd995f2c86 - Patch
References () https://github.com/gofiber/fiber/pull/4064 - () https://github.com/gofiber/fiber/pull/4064 - Exploit, Issue Tracking
References () https://github.com/gofiber/fiber/security/advisories/GHSA-m3c2-496v-cw3v - () https://github.com/gofiber/fiber/security/advisories/GHSA-m3c2-496v-cw3v - Exploit, Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
First Time Gofiber
Gofiber fiber
CPE cpe:2.3:a:gofiber:fiber:*:*:*:*:*:go:*:*

24 Feb 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-24 22:16

Updated : 2026-06-17 10:25


NVD link : CVE-2026-25891

Mitre link : CVE-2026-25891

CVE.ORG link : CVE-2026-25891


JSON object : View

Products Affected

gofiber

  • fiber
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')