CVE-2026-25882Disclosure(gofiber / fiber)

LOWCVSS 7.5 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch gofiber fiber systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Fiber is an Express inspired web framework written in Go. A denial of service vulnerability exists in Fiber v2 and v3 that allows remote attackers to crash the application by sending requests to routes with more than 30 parameters. The vulnerability results from missing validation during route registration combined with an unbounded array write during request matching. Version 2.52.12 patches the issue in the v2 branch and 3.1.0 patches the issue in the v3 branch.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-129

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fiber

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • Peaked at 3 mentions on most recent observed day (2026-02-25)
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
fiber

Deep dive

Activity timeline5 mentions / 2d
01223Mentions · 2026-02-24: 2Mentions · 2026-02-25: 3Patch / Workaround · 2026-02-24: 1Technical Details · 2026-02-24: 2Technical Details · 2026-02-25: 302-2402-25
Signal classification2 categories
Disclosure
480.0%
Patch
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-242
Disclosure1Patch1
2026-02-253
Disclosure3
Full discourse5 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-25882 Fiber is an Express inspired web framework written in Go. A denial of service vulnerability exists in Fiber v2 and v3 that allows remote attackers to crash the applic… https://www.cve.org/CVERecord?id=CVE-2026-25882

    Post summary

    A denial‑of‑service vulnerability in Fiber v2 and v3 allows remote attackers to crash the application.

    00010368
    56.6K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-25882 Fiber is an Express inspired web framework written in Go. A denial of service vulnerability exists in Fiber v2 and v3 that allows remote attackers to crash the applic… https://www.cve.org/CVERecord?id=CVE-2026-25882 ----- Traducción: CVE-2026-25882 Fib… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-25882, a denial‑of‑service flaw in Fiber v2 and v3 that allows remote attackers to crash the application; no PoC, exploit, patch, or active exploitation is reported.

    0000039
    54 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-25882 Denial of Service Vulnerability in Fiber Web Framework Versions 2 and 3 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25882

    Post summary

    A Denial of Service vulnerability (CVE-2026-25882) affecting Fiber Web Framework versions 2 and 3 has been identified, with a link to a vulnerability database entry.

    0000036
    4.0K followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-25882: Panic at the Router: Crashing Go Fiber with a Single Request A critical Denial of Service (DoS) vulnerability exists in the Fiber web framework (v2 and v3) due to an unchecked array index write. By defining a route with more than 30 pa... https://cvereports.com/reports/CVE-2026-25882

    Post summary

    The article announces a critical DoS vulnerability in the Fiber web framework caused by an unchecked array index write, but it does not provide a PoC, exploit code, patch, or evidence of active exploitation.

    0000043
    31 followersView on X
  • Volerion@VolerionSec
    Patch

    🚨 CVE-2026-25882: One request with 30+ route params can crash any Fiber app, bringing your service down. Upgrade to 2.52.12 / 3.0.1+ or audit routes and add rate limits. Full advisory ➡️ https://volerion.com/vulnerabilities/CVE-2026-25882 #GoFiber #infosec #DevOps

    Post summary

    CVE-2026-25882 causes a crash in GoFiber applications via a request with many route parameters; the advisory recommends upgrading to 2.52.12 / 3.0.1+ or applying rate limits to mitigate the issue.

    0000046
    51 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgofiberfiber-go-

Explore more