CVE-2026-25891

HIGH

Fiber v3 <3.0.0 - Path Traversal

Title source: llm
STIX 2.1

Description

Fiber is an Express inspired web framework written in Go. A Path Traversal (CWE-22) vulnerability in Fiber allows a remote attacker to bypass the static middleware sanitizer and read arbitrary files on the server file system on Windows. This affects Fiber v3 through version 3.0.0. This has been patched in Fiber v3 version 3.1.0.

Scores

CVSS v3 7.5
EPSS 0.0004
EPSS Percentile 10.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (2)
gofiber/fiber 0 - 3.1.0Go
gofiber/fiber 3.0.0 - 3.1.0
Published Feb 24, 2026
Tracked Since Feb 25, 2026