
We found results for “”
CVE-2025-48075
Good to know:

Date: May 22, 2025
Fiber is an Express-inspired web framework written in Go. Starting in version 2.52.6 and prior to version 2.52.7, "fiber.Ctx.BodyParser" can map flat data to nested slices using "key[idx]value" syntax, but when idx is negative, it causes a panic instead of returning an error stating it cannot process the data. Since this data is user-provided, this could lead to denial of service for anyone relying on this "fiber.Ctx.BodyParser" functionality. Version 2.52.7 fixes the issue.
Severity Score
Related Resources (6)
Severity Score
Weakness Type (CWE)
Improper Validation of Array Index
CWE-129Top Fix

Upgrade Version
Upgrade to version github.com/gofiber/fiber/v2 - v2.52.7;https://github.com/gofiber/fiber.git - v2.52.7
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | NONE |
User Interaction (UI): | NONE |
Scope (S): | UNCHANGED |
Confidentiality (C): | NONE |
Integrity (I): | NONE |
Availability (A): | HIGH |