
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-25899 is a Denial of Service vulnerability in GoFiber (Fiber), an Express-inspired web framework written in Go, caused by unbounded memory allocation via unvalidated msgpack deserialization of the fiber_flash cookie. It affects all Fiber v3 releases from 3.0.0 up to (but not including) 3.1.0. A crafted 10-character cookie value can force the server to attempt allocating up to 85GB of memory, with no authentication required. It was published on February 24, 2026, and carries a CVSS v3.1 base score of 7.5 (High) (GitHub Advisory, Fiber Security Advisory).
The root cause is classified under CWE-789 (Memory Allocation with Excessive Size Value) and CWE-770 (Allocation of Resources Without Limits or Throttling). Fiber's request handler unconditionally checks for the fiber_flash cookie on every incoming request, regardless of whether the application uses flash messages. When the cookie is present, the value is hex-decoded and passed directly to redirectionMsgs.UnmarshalMsg() — auto-generated msgpack deserialization code from tinylib/msgp — which reads a uint32 array header from the attacker-controlled byte stream and passes it directly to make() with no bounds check. The crafted payload dd7fffffff (a hex-encoded msgpack array32 marker with 2,147,483,647 elements) triggers an attempt to allocate approximately 85GB of memory, crashing the server (GitHub Advisory, Fiber Security Advisory).
Successful exploitation results in complete service unavailability (Denial of Service) for the affected GoFiber v3 server. Because the vulnerable flash cookie parsing is hardcoded into the request handler and triggered on every request to every endpoint, there is no way to isolate or limit exposure at the application level without patching. There is no confidentiality or integrity impact — the vulnerability is purely an availability risk — but a single unauthenticated HTTP request with a 10-character cookie value is sufficient to crash the server (GitHub Advisory, Fiber Security Advisory).
A proof-of-concept exploit is publicly documented in the GitHub Security Advisory, consisting of a single curl command: curl -H "Cookie: fiber_flash=dd7fffffff" http://<target>/. No authentication, special privileges, or user interaction is required, and attack complexity is low. There is no current evidence of in-the-wild exploitation or threat actor attribution. The EPSS score is approximately 0.064–0.132%, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog as of the time of this report (GitHub Advisory, Fiber Security Advisory).
fiber_flash cookie value of dd7fffffff, which is a hex-encoded msgpack array32 header (dd = array32 marker, 7fffffff = 2,147,483,647 elements).curl -H "Cookie: fiber_flash=dd7fffffff" http://<target>:<port>/<any-endpoint>fiber_flash cookie, hex-decodes the value, and passes it to UnmarshalMsg(), which calls make(redirectionMsgs, 2147483647), attempting to allocate ~85GB of memory.Cookie: fiber_flash=dd7fffffff header (or similar short hex-encoded msgpack array32 payloads beginning with dd followed by a large value); repeated requests from a single IP or distributed sources targeting any server endpoint with the fiber_flash cookie.fiber_flash cookie values that are short (≤10 characters) and hex-encoded; sudden spike in request volume with fiber_flash cookie present across multiple endpoints./var/log/syslog, dmesg) referencing the Fiber application process; unexpected process crashes or restarts of the GoFiber application.redirectionMsgs.UnmarshalMsg or msgp.ReadArrayHeaderBytes in stack traces (GitHub Advisory).The primary remediation is to upgrade GoFiber v3 to version 3.1.0 or later, which applies limits to msgpack serialization and hardens flash cookie detection (see release notes: apply limits to msgp serialization (#4065) and harden flash cookie detection (#4078)). No configuration-based workaround is available since the vulnerable flash cookie parsing is hardcoded into the request handler and cannot be disabled at the application level without patching. Organizations should treat this as a high-priority update for all GoFiber v3 deployments, regardless of whether the application uses flash messages (Fiber Release v3.1.0, GitHub Advisory).
The vulnerability was reported by security researcher tuliperis and remediated by GoFiber maintainer gaby, with the advisory published by ReneWerner87 on February 24, 2026. Social media coverage appeared on Mastodon and Bluesky shortly after disclosure, with posts from accounts such as @thehackerwire and @cyberhub.blog highlighting the trivial exploit payload and unauthenticated nature of the attack. Security news aggregators including Digg, InfinitSec, and INCIBE (Spain's national cybersecurity agency) also covered the disclosure (GitHub Advisory, Fiber Security Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."