Volerion[verified]@VolerionSecPatch
CVE-2026-25899 is a denial‑of‑service flaw in GoFiber ≤3.0 triggered by a crafted fiber_flash cookie that can exhaust 85 GB of RAM; patch to 3.1.0+ or block the cookie is recommended.
Infoflowcloud@infoflowcloudDisclosure
A new CVE-2026-25899 affecting the Fiber Go framework is disclosed, noting an unbounded allocation via the `fiber_flash` cookie in versions before 3.1.0.
CVE@CVEnewDisclosure
The text announces CVE-2026-25899, describing an unbounded allocation vulnerability in Fiber’s flash cookie handling for versions before 3.1.0, but it does not provide a PoC, exploit, or patch details.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
A new unbounded memory allocation vulnerability (CVE-2026-25899) has been identified in GoFiber v3, with details available on Vulmon.
cvereports@_cvereportsDisclosure
A critical DoS vulnerability in GoFiber v3’s flash message handling is disclosed, but no PoC, exploit, or patch details are provided.