CVE-2025-54801
CVE-2025-54801 is a high-severity vulnerability in Gofiber Fiber with a CVSS 3.x base score of 7.5. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-789.
Key facts
- Severity: High (CVSS 3.x base score 7.5)
- CVSS v4: 8.7
- EPSS exploit prediction: 0% (29th percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2025-23668
- Weakness: CWE-789
- Affected product: Gofiber Fiber
- Published:
- Last modified:
Description
Fiber is an Express inspired web framework written in Go. In versions 2.52.8 and below, when using Fiber's Ctx.BodyParser to parse form data containing a large numeric key that represents a slice index (e.g., test.18446744073704), the application crashes due to an out-of-bounds slice allocation in the underlying schema decoder. The root cause is that the decoder attempts to allocate a slice of length idx + 1 without validating whether the index is within a safe or reasonable range. If the idx is excessively large, this leads to an integer overflow or memory exhaustion, causing a panic or crash. This is fixed in version 2.52.9.
Frequently asked questions
- What is CVE-2025-54801?
- Fiber is an Express inspired web framework written in Go. In versions 2.52.8 and below, when using Fiber's Ctx.BodyParser to parse form data containing a large numeric key that represents a slice index (e.g., test.18446744073704), the application crashes due to an out-of-bounds slice allocation in the underlying schema decoder. The root cause is that the decoder attempts to allocate a slice of length idx + 1 without validating whether the index is within a safe or reasonable range. If the idx is excessively large, this leads to an integer overflow or memory exhaustion, causing a panic or crash. This is fixed in version 2.52.9.
- How severe is CVE-2025-54801?
- CVE-2025-54801 has a CVSS 3.x base score of 7.5, rated high severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is none, integrity none, and availability high.
- Is CVE-2025-54801 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (29th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2025-54801?
- CVE-2025-54801 affects Gofiber Fiber. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2025-54801?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- Does CVE-2025-54801 have an EU (EUVD) identifier?
- Yes. CVE-2025-54801 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2025-23668.
- When was CVE-2025-54801 published?
- CVE-2025-54801 was published on 2025-08-06 and last updated on 2026-06-17.
References
- https://github.com/gofiber/fiber/commit/e115c08b8f059a4a031b492aa9eef0712411853d
- https://github.com/gofiber/fiber/security/advisories/GHSA-qx2q-88mx-vhg7
Affected products (1)
- cpe:2.3:a:gofiber:fiber:*:*:*:*:*:go:*:*
More vulnerabilities in Gofiber Fiber
- CVE-2024-38513 — Critical (CVSS 10.0): Fiber is an Express-inspired web framework written in Go A vulnerability present in versions prior to 2.52.5 is a…
- CVE-2023-45128 — Critical (CVSS 10.0): Fiber is an express inspired web framework written in Go. A Cross-Site Request Forgery (CSRF) vulnerability has been…
- CVE-2025-66630 — Critical (CVSS 9.4): Fiber is an Express inspired web framework written in Go. Before 2.52.11, on Go versions prior to 1.24, the underlying…
- CVE-2024-25124 — Critical (CVSS 9.4): Fiber is a web framework written in go. Prior to version 2.52.1, the CORS middleware allows for insecure configurations…
- CVE-2023-45141 — High (CVSS 8.6): Fiber is an express inspired web framework written in Go. A Cross-Site Request Forgery (CSRF) vulnerability has been…
- CVE-2026-25899 — High (CVSS 7.5): Fiber is an Express inspired web framework written in Go. In versions on the v3 branch prior to 3.1.0, the use of the…
All CVEs affecting Gofiber Fiber →
Other CWE-789 vulnerabilities
- CVE-2021-34869 — High (CVSS 8.8): This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop…
- CVE-2021-34868 — High (CVSS 8.8): This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop…
- CVE-2026-69219 — High (CVSS 8.7): The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes.…
- CVE-2026-58067 — High (CVSS 8.7): A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to exhaust host memory and cause…
- CVE-2026-14682 — High (CVSS 8.7): In Bouncy Castle for Java before 1.85, Possible OOM from unbounded up-front allocation on a definite-length read. This…
- CVE-2026-12852 — High (CVSS 8.7): In Bouncy Castle for Java before 1.85, MLS wire decoder allocates attacker-declared opaque length before bounds check.