Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-45045

Опубликовано: 08 июл. 2026
Источник: nvd
CVSS3: 5.3
EPSS Низкий

Описание

Fiber is an Express inspired web framework written in Go. Prior to 3.3.0 and 2.52.14, the BalancerForward proxy helper in middleware/proxy/proxy.go uses Header.Add() instead of Header.Set() when injecting X-Real-IP, allowing an attacker-supplied first X-Real-IP value to be forwarded to upstream servers for logging, rate limiting, and access control. This issue is fixed in version 3.3.0 and 2.52.14.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:gofiber:fiber:*:*:*:*:*:go:*:*
Версия до 2.52.14 (исключая)
cpe:2.3:a:gofiber:fiber:*:*:*:*:*:go:*:*
Версия от 3.0.0 (включая) до 3.3.0 (исключая)

EPSS

Процентиль: 39%
0.00463
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-290

Связанные уязвимости

CVSS3: 5.3
ubuntu
2 месяца назад

Fiber is an Express inspired web framework written in Go. Prior to 3.3.0 and 2.52.14, the BalancerForward proxy helper in middleware/proxy/proxy.go uses Header.Add() instead of Header.Set() when injecting X-Real-IP, allowing an attacker-supplied first X-Real-IP value to be forwarded to upstream servers for logging, rate limiting, and access control. This issue is fixed in version 3.3.0 and 2.52.14.

CVSS3: 5.3
github
2 месяца назад

GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward

EPSS

Процентиль: 39%
0.00463
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-290