Description
Fiber is an Express inspired web framework written in Go. A Path Traversal (CWE-22) vulnerability in Fiber allows a remote attacker to bypass the static middleware sanitizer and read arbitrary files on the server file system on Windows. This affects Fiber v3 through version 3.0.0. This has been patched in Fiber v3 version 3.1.0.
References (3)
Core 3
Core References
Vendor Advisory x_refsource_confirm
https://github.com/gofiber/fiber/security/advisories/GHSA-m3c2-496v-cw3v
Issue Tracking x_refsource_misc
https://github.com/gofiber/fiber/pull/4064
Patch x_refsource_misc
https://github.com/gofiber/fiber/commit/59133702301c2ab7b776dd123b474cbd995f2c86
Scores
CVSS v3
7.5
EPSS
0.0004
EPSS Percentile
10.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-22
Status
published
Products (2)
gofiber/fiber
0 - 3.1.0Go
gofiber/fiber
3.0.0 - 3.1.0
Published
Feb 24, 2026
Tracked Since
Feb 25, 2026