CVE-2026-25891Disclosure(gofiber / fiber)

LOWCVSS 7.5 · HIGH

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Patch gofiber fiber systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Fiber is an Express inspired web framework written in Go. A Path Traversal (CWE-22) vulnerability in Fiber allows a remote attacker to bypass the static middleware sanitizer and read arbitrary files on the server file system on Windows. This affects Fiber v3 through version 3.0.0. This has been patched in Fiber v3 version 3.1.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fiber

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • Peaked at 4 mentions on most recent observed day (2026-02-25)
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
fiber

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-02-24: 1Mentions · 2026-02-25: 4Patch / Workaround · 2026-02-24: 1Technical Details · 2026-02-24: 1Technical Details · 2026-02-25: 402-2402-25
Signal classification2 categories
Disclosure
480.0%
Patch
120.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-02-241
Patch1
2026-02-254
Disclosure4
Full discourse5 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-25891 Fiber is an Express inspired web framework written in Go. A Path Traversal (CWE-22) vulnerability in Fiber allows a remote attacker to bypass the static middleware sa… https://www.cve.org/CVERecord?id=CVE-2026-25891 ----- Traducción: CVE-2026-25891 Fib… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑25891, a path traversal flaw in the Fiber Go framework that lets attackers bypass static middleware. No PoC, exploit, or patch details are provided.

    0000038
    54 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25891 Fiber is an Express inspired web framework written in Go. A Path Traversal (CWE-22) vulnerability in Fiber allows a remote attacker to bypass the static middleware sa… https://www.cve.org/CVERecord?id=CVE-2026-25891

    Post summary

    The text announces a Path Traversal (CWE-22) vulnerability in the Fiber Go web framework, identified as CVE-2026-25891, without providing details on exploitation or mitigation.

    00000262
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-25891 Path Traversal in Fiber Web Framework v3.0.0 on Windows Servers https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25891 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    A path traversal vulnerability (CVE-2026-25891) affecting Fiber Web Framework v3.0.0 on Windows Servers has been disclosed, with details available on Vulmon.

    0000046
    4.0K followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-25891: Fiber's Windows Hangover: The Double-Decode Path Traversal A high-severity Path Traversal vulnerability in the Fiber Go framework (v3) allows remote attackers to read arbitrary files on Windows servers. By exploiting a logic flaw in th... https://cvereports.com/reports/CVE-2026-25891

    Post summary

    The report announces a high‑severity path‑traversal flaw in Fiber v3 that lets attackers read arbitrary files on Windows servers, but no PoC, exploit, or patch is mentioned.

    0000046
    31 followersView on X
  • Volerion@VolerionSec
    Patch

    🚨 CVE-2026-25891: Remote path traversal in Fiber ≤3.0.0 on Windows lets attackers read files outside the web root, exposing secrets. Upgrade to 3.1.0 ASAP! Full advisory ➡️ https://volerion.com/vulnerabilities/CVE-2026-25891 #GoFiber #infosec #AppSec

    Post summary

    The advisory highlights a remote path traversal vulnerability in GoFiber ≤3.0.0 on Windows, advises upgrading to 3.1.0, and links to the full advisory for details.

    0000049
    51 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgofiberfiber-go-

Explore more