CVE-2026-25899Disclosure(gofiber / fiber)

LOWCVSS 7.5 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch gofiber fiber systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Fiber is an Express inspired web framework written in Go. In versions on the v3 branch prior to 3.1.0, the use of the `fiber_flash` cookie can force an unbounded allocation on any server. A crafted 10-character cookie value triggers an attempt to allocate up to 85GB of memory via unvalidated msgpack deserialization. No authentication is required. Every GoFiber v3 endpoint is affected regardless of whether the application uses flash messages. Version 3.1.0 fixes the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-789CWE-770

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fiber

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • Peaked at 3 mentions on most recent observed day (2026-02-25)
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
fiber

Deep dive

Activity timeline5 mentions / 2d
01223Mentions · 2026-02-24: 2Mentions · 2026-02-25: 3Patch / Workaround · 2026-02-24: 1Technical Details · 2026-02-24: 2Technical Details · 2026-02-25: 302-2402-25
Signal classification2 categories
Disclosure
480.0%
Patch
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-242
Disclosure1Patch1
2026-02-253
Disclosure3
Full discourse5 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-25899 Fiber is an Express inspired web framework written in Go. In versions on the v3 branch prior to 3.1.0, the use of the `fiber_flash` cookie can force an unbounded allo… https://www.cve.org/CVERecord?id=CVE-2026-25899 ----- Traducción: CVE-2026-25899 Fib… http://infoflow.cloud`

    Post summary

    A new CVE-2026-25899 affecting the Fiber Go framework is disclosed, noting an unbounded allocation via the `fiber_flash` cookie in versions before 3.1.0.

    0000041
    54 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25899 Fiber is an Express inspired web framework written in Go. In versions on the v3 branch prior to 3.1.0, the use of the `fiber_flash` cookie can force an unbounded allo… https://www.cve.org/CVERecord?id=CVE-2026-25899

    Post summary

    The text announces CVE-2026-25899, describing an unbounded allocation vulnerability in Fiber’s flash cookie handling for versions before 3.1.0, but it does not provide a PoC, exploit, or patch details.

    00000270
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-25899 Unbounded Memory Allocation Vulnerability in GoFiber v3 Web Framework https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25899

    Post summary

    A new unbounded memory allocation vulnerability (CVE-2026-25899) has been identified in GoFiber v3, with details available on Vulmon.

    0000046
    4.0K followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-25899: The 10-Byte Killer: How a Tiny Cookie Crushed GoFiber v3 GoFiber v3, a framework renowned for its blistering speed, fell victim to a critical Denial of Service vulnerability rooted in its handling of flash messages. By sending a specia... https://cvereports.com/reports/CVE-2026-25899

    Post summary

    A critical DoS vulnerability in GoFiber v3’s flash message handling is disclosed, but no PoC, exploit, or patch details are provided.

    0000048
    31 followersView on X
  • Volerion@VolerionSec
    Patch

    🚨 CVE-2026-25899: A crafted fiber_flash cookie lets anyone crash GoFiber ≤3.0 by forcing an 85 GB RAM grab. Patch to 3.1.0+ or block the cookie ASAP. Full advisory ➡️ https://volerion.com/vulnerabilities/CVE-2026-25899 #GoFiber #infosec #AppSec

    Post summary

    CVE-2026-25899 is a denial‑of‑service flaw in GoFiber ≤3.0 triggered by a crafted fiber_flash cookie that can exhaust 85 GB of RAM; patch to 3.1.0+ or block the cookie is recommended.

    0000050
    51 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgofiberfiber-go-

Explore more