Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 2

Количество 2

nvd логотип

CVE-2026-25899

5 месяцев назад

Fiber is an Express inspired web framework written in Go. In versions on the v3 branch prior to 3.1.0, the use of the `fiber_flash` cookie can force an unbounded allocation on any server. A crafted 10-character cookie value triggers an attempt to allocate up to 85GB of memory via unvalidated msgpack deserialization. No authentication is required. Every GoFiber v3 endpoint is affected regardless of whether the application uses flash messages. Version 3.1.0 fixes the issue.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2mr3-m5q5-wgp6

5 месяцев назад

Fiber is Vulnerable to Denial of Service via Flash Cookie Unbounded Allocation

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-25899

Fiber is an Express inspired web framework written in Go. In versions on the v3 branch prior to 3.1.0, the use of the `fiber_flash` cookie can force an unbounded allocation on any server. A crafted 10-character cookie value triggers an attempt to allocate up to 85GB of memory via unvalidated msgpack deserialization. No authentication is required. Every GoFiber v3 endpoint is affected regardless of whether the application uses flash messages. Version 3.1.0 fixes the issue.

CVSS3: 7.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-2mr3-m5q5-wgp6

Fiber is Vulnerable to Denial of Service via Flash Cookie Unbounded Allocation

CVSS3: 7.5
0%
Низкий
5 месяцев назад

Уязвимостей на страницу