Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-25891

Fiber is an Express inspired web framework written in Go. A Path Traversal (CWE-22) vulnerability in Fiber allows a remote attacker to bypass the static middleware sanitizer and read arbitrary files on the server file system on Windows. This affects Fiber v3 through version 3.0.0. This has been patched in Fiber v3 version 3.1.0.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 5.9%
CVSS Severity
CVSS v3 Score 7.5
Products affected by CVE-2026-25891
  • Gofiber » Fiber » Version: Any
    cpe:2.3:a:gofiber:fiber:*


Contact Us

Shodan ® - All rights reserved