HIGH7.5CVE-2026-25899Fiber is Vulnerable to Denial of Service via Flash Cookie Unbounded Allocation in github.com/gofiber/fiber/v3 from 0, < 3.1.0
HIGH7.5CVE-2026-25899Fiber is Vulnerable to Denial of Service via Flash Cookie Unbounded Allocation in github.com/gofiber/fiber/v3 from 0, < 3.1.0
MEDIUM6.5CVE-2026-30246Fiber's cache middleware default key generator ignores query string, causing response mix-up across distinct query parameters from 0, < 3.2.0
MEDIUM5.3GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward
from 0, < 3.3.0
MEDIUM5.3GoFiber Vulnerable to Username Enumeration via Timing Oracle in BasicAuth Default Authorizer
from 0, < 3.3.0
—Fiber vulnerable to XSS in AutoFormat Content Negotiation
from 0, < 3.2.0
—Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber
from 0, < 3.1.0
—Fiber has a Denial of Service Vulnerability via Route Parameter Overflow in github.com/gofiber/fiber
from 0, < 3.1.0
—Fiber has an Arbitrary File Read in Static Middleware on Windows in github.com/gofiber/fiber/v3
from 0, < 3.1.0
—Fiber has an Arbitrary File Read in Static Middleware on Windows in github.com/gofiber/fiber/v3
from 0, < 3.1.0