CVE-2026-25882: 
Wolfi vulnerability analysis and mitigation

Overview

CVE-2026-25882 is a Denial of Service (DoS) vulnerability in the Go web framework Fiber (gofiber/fiber) affecting both v2 and v3 branches. It allows unauthenticated remote attackers to crash a Fiber application by sending HTTP requests to routes registered with more than 30 parameters, triggering a Go runtime panic. Affected versions include Fiber v2 from 2.0.0 up to (but not including) 2.52.12, and Fiber v3 from 3.0.0 up to (but not including) 3.1.0. The vulnerability was discovered on December 24, 2024, and publicly disclosed via GitHub Advisory on February 24, 2026. It carries a CVSS v3.1 base score of 7.5 (High) (Github Advisory, Fiber Security Advisory).

Technical details

The root cause is classified as CWE-129 (Improper Validation of Array Index). Both Fiber v2 and v3 define a fixed-size parameter array of 30 elements (const maxParams = 30; type DefaultCtx struct { values [maxParams]string }) in ctx.go. The router.go register() function accepts route registrations without validating the number of parameters, so routes with more than 30 named parameters can be registered without error. During request matching, path.go (v3: line 514, v2: line 516) performs an unbounded write — params[paramsIterator] = path[:i] — without checking whether paramsIterator has exceeded the array bounds. When a matching request arrives for such a route, paramsIterator reaches 30 or higher, triggering a Go runtime panic: index out of range [30] with length 30. Full proof-of-concept code for both v2 and v3 is publicly available in the security advisory (Github Advisory, Fiber Security Advisory).

Impact

Successful exploitation causes the Fiber application process to crash immediately via an unrecovered Go runtime panic, resulting in complete service unavailability for all users. No authentication is required, and a single crafted HTTP GET request is sufficient to trigger the crash, making sustained DoS attacks trivial to script. There is no confidentiality or integrity impact — the vulnerability is limited to availability. In microservice architectures, a crash of a vulnerable Fiber service could trigger cascade failures in dependent services, and auto-scaling mechanisms may be unable to recover if the crash is repeatedly triggered (Github Advisory, Fiber Security Advisory).

Exploitability

Proof-of-concept exploit code for both Fiber v2 and v3 is publicly available in the GitHub Security Advisory (Github Advisory). The CVSS v4 exploit maturity is rated "Proof of Concept." As of the time of disclosure, there is no evidence of in-the-wild exploitation or known threat actor attribution. The EPSS score is approximately 0.041% (0.000410), placing it in the 24th percentile for exploitation probability within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires only knowledge of a vulnerable route structure (often publicly documented in APIs) and a standard HTTP client (Fiber Security Advisory).

Exploitation steps

  1. Reconnaissance: Identify target applications built with Fiber v2 (< 2.52.12) or v3 (< 3.1.0) using version disclosure headers, open-source intelligence, or API documentation. Look for routes with many path parameters (e.g., REST APIs with deeply nested resource paths).
  2. Identify a vulnerable route: Determine or infer a route registered with more than 30 named parameters (e.g., /api/:p1/:p2/.../:p35). This information may be available in public API docs, source code repositories, or through fuzzing.
  3. Craft the exploit request: Build an HTTP GET request URL matching the vulnerable route with 31 or more parameter values, e.g.:
    curl http://target/api/v1/v2/v3/v4/v5/v6/v7/v8/v9/v10/v11/v12/v13/v14/v15/v16/v17/v18/v19/v20/v21/v22/v23/v24/v25/v26/v27/v28/v29/v30/v31
  4. Send the request: Transmit the crafted request to the target server. No authentication headers or special encoding are required.
  5. Observe crash: The server's Fiber process panics with runtime error: index out of range [30] with length 30 in path.go, crashing the application and causing service unavailability.
  6. Sustain DoS: Repeat the request in a loop to prevent service recovery, as each restart will crash again upon receiving the same request (Github Advisory, Fiber Security Advisory).

Indicators of compromise

  • Logs: Application logs containing Go runtime panic messages such as panic: runtime error: index out of range [30] with length 30 with stack traces referencing path.go:514 (v3) or path.go:516 (v2), router.go, and (*routeParser).getMatch.
  • Logs: Repeated HTTP requests to the same deeply-parameterized route path in access logs, especially from a single or small set of source IPs.
  • Network: Unusual HTTP GET requests with 31 or more path segments matching a registered parameterized route pattern, originating from unexpected or external IP addresses.
  • Process: Sudden, repeated termination and restart of the Fiber application process (observable via process monitoring, container restarts, or service manager logs such as systemd or Kubernetes pod restart counts).
  • Monitoring: Spike in application error rates or availability alerts coinciding with requests to specific route patterns (Github Advisory).

Mitigation and workarounds

Upgrade immediately to the patched versions: Fiber v2.52.12 or later, or Fiber v3.1.0 or later. Until patching is possible, the following workarounds can reduce risk:

  • Audit routes: Ensure no registered routes have more than 30 named parameters. Use grep -r '/:.*/:.*/:.*' . to identify candidates.
  • Validate dynamic routes: If routes are registered programmatically, add a parameter count check before registration: if strings.Count(route, ":") > 30 { log.Fatal("Route exceeds maxParams") }.
  • Rate limiting: Deploy aggressive rate limiting at the network or API gateway layer to reduce the impact of repeated crash attempts.
  • Monitoring: Configure alerts for panic patterns in application logs to detect exploitation attempts quickly (Github Advisory, Fiber Security Advisory).

Community reactions

The vulnerability was discovered by Fiber maintainer @sixcolors and @TheAspectDev during a code review of PR #3962 (the OverrideParam feature), and the security advisory was published by maintainer ReneWerner87 on February 24, 2026. Coverage has been picked up by several vulnerability tracking and security news aggregators including infinitsec.net, The Hacker Wire, and INCIBE-CERT, as well as standard CVE feeds. Community reaction has been limited given the moderate severity and the requirement for routes with an unusually high parameter count, but the availability of public PoC code has been noted (Github Advisory, Fiber Security Advisory).

Additional resources


Source: This report was generated using AI

Related Wolfi vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-103000HIGH8.7
  • Python logoPython
  • litellm-1.101
NoYesSep 30, 2026
CVE-2026-102999HIGH8.7
  • Python logoPython
  • litellm-1.98
NoYesSep 30, 2026
CVE-2026-102998HIGH8.7
  • Python logoPython
  • litellm-1.98
NoYesSep 30, 2026
CVE-2026-102997HIGH8.7
  • Python logoPython
  • pypdf
NoYesSep 30, 2026
CVE-2026-77387MEDIUM4
  • Python logoPython
  • superset-6.1
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management