MEDIUMGo →
GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward
GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward
Affected packages
- github.com/gofiber/fiber/v2
- github.com/gofiber/fiber/v3
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- 0.36%
- EPSS percentile
- 29.0%
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs. This advisory is in the top 29%.
Sources
- https://github.com/gofiber/fiber/security/advisories/GHSA-gcfq-8gqf-4876
- https://nvd.nist.gov/vuln/detail/CVE-2026-45045
- https://github.com/gofiber/fiber/pull/4260
- https://github.com/gofiber/fiber/pull/4495
- https://github.com/gofiber/fiber/commit/1403cc8292da3220e9316960b4030cc722a0f396
- https://github.com/gofiber/fiber/commit/33c9501288ab47a429c8b5e701493f0c3c0af37d
- https://github.com/gofiber/fiber
- https://github.com/gofiber/fiber/releases/tag/v2.52.14
- https://github.com/gofiber/fiber/releases/tag/v3.3.0
Structured record: https://osv.dev/vulnerability/GHSA-gcfq-8gqf-4876
Recommended response stack
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta