
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-25882 is a Denial of Service (DoS) vulnerability in the Go web framework Fiber (gofiber/fiber) affecting both v2 and v3 branches. It allows unauthenticated remote attackers to crash a Fiber application by sending HTTP requests to routes registered with more than 30 parameters, triggering a Go runtime panic. Affected versions include Fiber v2 from 2.0.0 up to (but not including) 2.52.12, and Fiber v3 from 3.0.0 up to (but not including) 3.1.0. The vulnerability was discovered on December 24, 2024, and publicly disclosed via GitHub Advisory on February 24, 2026. It carries a CVSS v3.1 base score of 7.5 (High) (Github Advisory, Fiber Security Advisory).
The root cause is classified as CWE-129 (Improper Validation of Array Index). Both Fiber v2 and v3 define a fixed-size parameter array of 30 elements (const maxParams = 30; type DefaultCtx struct { values [maxParams]string }) in ctx.go. The router.go register() function accepts route registrations without validating the number of parameters, so routes with more than 30 named parameters can be registered without error. During request matching, path.go (v3: line 514, v2: line 516) performs an unbounded write — params[paramsIterator] = path[:i] — without checking whether paramsIterator has exceeded the array bounds. When a matching request arrives for such a route, paramsIterator reaches 30 or higher, triggering a Go runtime panic: index out of range [30] with length 30. Full proof-of-concept code for both v2 and v3 is publicly available in the security advisory (Github Advisory, Fiber Security Advisory).
Successful exploitation causes the Fiber application process to crash immediately via an unrecovered Go runtime panic, resulting in complete service unavailability for all users. No authentication is required, and a single crafted HTTP GET request is sufficient to trigger the crash, making sustained DoS attacks trivial to script. There is no confidentiality or integrity impact — the vulnerability is limited to availability. In microservice architectures, a crash of a vulnerable Fiber service could trigger cascade failures in dependent services, and auto-scaling mechanisms may be unable to recover if the crash is repeatedly triggered (Github Advisory, Fiber Security Advisory).
Proof-of-concept exploit code for both Fiber v2 and v3 is publicly available in the GitHub Security Advisory (Github Advisory). The CVSS v4 exploit maturity is rated "Proof of Concept." As of the time of disclosure, there is no evidence of in-the-wild exploitation or known threat actor attribution. The EPSS score is approximately 0.041% (0.000410), placing it in the 24th percentile for exploitation probability within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires only knowledge of a vulnerable route structure (often publicly documented in APIs) and a standard HTTP client (Fiber Security Advisory).
/api/:p1/:p2/.../:p35). This information may be available in public API docs, source code repositories, or through fuzzing.curl http://target/api/v1/v2/v3/v4/v5/v6/v7/v8/v9/v10/v11/v12/v13/v14/v15/v16/v17/v18/v19/v20/v21/v22/v23/v24/v25/v26/v27/v28/v29/v30/v31runtime error: index out of range [30] with length 30 in path.go, crashing the application and causing service unavailability.panic: runtime error: index out of range [30] with length 30 with stack traces referencing path.go:514 (v3) or path.go:516 (v2), router.go, and (*routeParser).getMatch.Upgrade immediately to the patched versions: Fiber v2.52.12 or later, or Fiber v3.1.0 or later. Until patching is possible, the following workarounds can reduce risk:
grep -r '/:.*/:.*/:.*' . to identify candidates.if strings.Count(route, ":") > 30 { log.Fatal("Route exceeds maxParams") }.The vulnerability was discovered by Fiber maintainer @sixcolors and @TheAspectDev during a code review of PR #3962 (the OverrideParam feature), and the security advisory was published by maintainer ReneWerner87 on February 24, 2026. Coverage has been picked up by several vulnerability tracking and security news aggregators including infinitsec.net, The Hacker Wire, and INCIBE-CERT, as well as standard CVE feeds. Community reaction has been limited given the moderate severity and the requirement for routes with an unusually high parameter count, but the availability of public PoC code has been noted (Github Advisory, Fiber Security Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."