
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-25891 is a path traversal vulnerability (CWE-22) in the Go web framework Fiber's static middleware, allowing unauthenticated remote attackers to read arbitrary files on Windows servers. It affects all Fiber v3 prereleases through the stable release v3.0.0 (Go module github.com/gofiber/fiber/v3). The vulnerability was published on February 24, 2026, and patched in Fiber v3.1.0. It carries a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 7.7 (High) (GitHub Advisory, Fiber Security Advisory).
The vulnerability resides in the sanitizePath function within middleware/static/static.go. Two flaws combine to enable exploitation: first, the backslash character check occurs before the URL decoding loop, so a double-encoded backslash (%255C) passes the initial check; the loop then decodes it to a literal backslash (\). Second, the function uses Go's path.Clean, which only recognizes forward slashes as directory separators and treats backslash-based sequences like ..\.\ as valid filenames rather than traversal sequences. When the resulting path is passed to the Windows file system, backslashes are interpreted as directory separators, enabling traversal outside the web root (GitHub Advisory, Fiber Security Advisory). Exploitation requires no authentication and no user interaction, but is limited to Windows deployments using the static middleware, as only Windows treats backslashes as directory separators at the OS level.
Successful exploitation allows an unauthenticated remote attacker to read arbitrary files within the scope of the application server's process context on Windows. Depending on the server's file system permissions and deployment configuration, attackers may access sensitive files outside the web root — including application configuration files, source code, environment files containing secrets, or Windows system files (e.g., C:\Windows\win.ini, drivers\etc\hosts). There is no integrity or availability impact; the vulnerability is purely a confidentiality breach. Exposure of application secrets (API keys, database credentials) frequently enables further compromise of downstream systems (GitHub Advisory, Feedly).
Proof-of-concept exploit details are publicly available via the GitHub pull request (#4064) and the security advisory, which document the double-encoded backslash bypass technique (Fiber PR #4064, Fiber Security Advisory). As of the time of disclosure, there is no evidence of active in-the-wild exploitation, and no threat actor attribution has been reported. The EPSS score is approximately 0.035% (11th percentile), indicating a low current probability of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The CVSS v4.0 exploit maturity is rated as "Proof of Concept."
/static/, /assets/, or /).C:\Windows\win.ini, send a request such as:GET /%255C..%255C..%255CWindows%255Cwin.ini HTTP/1.1
Host: target.example.comThe server decodes %255C → %5C → \, and path.Clean fails to resolve the traversal, allowing the Windows file system to interpret the backslashes as directory separators..env files, configuration files, or system files accessible to the server process account).%255C, %5C, %5c, or literal backslash characters in the URL path; requests with path segments such as ..%255C, ..%5C, or ..\ in the URL; requests targeting Windows-specific paths (e.g., win.ini, System32, drivers\etc\hosts).%255C) or encoded traversal patterns (%5C..%5C) in the request URI; HTTP 200 responses to requests containing traversal sequences against static file endpoints; repeated requests with varying traversal depths from the same source IP.The vulnerability is patched in Fiber v3.1.0; all users running Fiber v3.0.0 or earlier on Windows with the static middleware should upgrade immediately (GitHub Advisory, Fiber Security Advisory). The fix (commit 5913370, PR #4064) moves the backslash check to after URL decoding, adds filepath.ToSlash normalization, rejects residual .. segments, and blocks UNC paths and Windows drive-letter prefixes (Fiber Commit). If immediate patching is not possible, consider disabling or restricting access to the static middleware on Windows deployments, or placing a reverse proxy in front that rejects requests containing backslash-encoded sequences. Review access logs for exploitation attempts showing backslash path traversal patterns.
The vulnerability was reported by researcher wodzen and remediated by Fiber maintainer gaby, with the fix merged by ReneWerner87 on February 8, 2026, ahead of the public advisory on February 24, 2026 (Fiber Security Advisory). The Go vulnerability database tracked this as GO-2026-4540. Coverage appeared in security aggregators including Vulners, VulDB, and INCIBE-CERT shortly after disclosure. No significant broader media coverage or notable public researcher commentary beyond the official advisory and patch PR has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."