An open index of dependabot pull requests across open source projects.

github.com/gofiber/fiber/v2

Ecosystem:
go
Package URL:
pkg:golang/github.com/gofiber/fiber/v2
Total PRs:
1,209 Dependabot PRs
Latest PR:
1 day ago
Unique Repositories:
689 repositories
Unique Repos (30 days):
7 repositories
Security Advisories
Fiber has a Denial of Service Vulnerability via Route Parameter Overflow
GHSA-mrq8-rjmw-wpq3 CVE-2026-25882 MODERATE published 3 months ago • updated 3 days ago
A denial of service vulnerability exists in Fiber v2 and v3 that allows remote attackers to crash the application by sending requests to routes wit...
Fiber vulnerable to XSS in AutoFormat Content Negotiation
GHSA-qjv7-627w-8qjv CVE-2026-42554 MODERATE published 26 days ago • updated 3 days ago
## Summary **Description** A Cross-Site Scripting (CWE-79) vulnerability in Go Fiber allows a remote attacker to inject arbitrary HTML/JavaScript...
Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() — predictable / zero‑UUID on crypto/rand failure
GHSA-68rr-p4fp-j59v CVE-2025-66630 CRITICAL published 4 months ago • updated about 1 month ago
Fiber v2 contains an internal vendored copy of `gofiber/utils`, and its functions `UUIDv4()` and `UUID()` inherit the same critical weakness descri...
Fiber panics when fiber.Ctx.BodyParser parses invalid range index
GHSA-hg3g-gphw-5hhm CVE-2025-48075 HIGH published about 1 year ago • updated about 1 month ago
### Summary When using the `fiber.Ctx.BodyParser` to parse into a struct with range values, a panic occurs when trying to parse a negative range in...
Go Fiber CSRF Token Validation Vulnerability
GHSA-mv73-f69x-444p CVE-2023-45141 HIGH published over 2 years ago • updated about 1 month ago
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the application, which allows an attacker to obtain tokens and forge malic...
Recent PRs
Package Details
Name: github.com/gofiber/fiber/v2
Ecosystem: go
PURL Type: golang
Package URL: pkg:golang/github.com/gofiber/fiber/v2
JSON API: View JSON
Security Advisories

10

Active advisories
CRITICAL 4
HIGH 3
MODERATE 3
View All golang Advisories
Package Information
Description:

Package fiber is an Express inspired web framework built on top of Fasthttp, the fastest HTTP engine for Go. Designed to ease things up for fast development with zero memory allocation and performance in mind.

Repository: https://github.com/gofiber/fiber
Homepage: https://github.com/gofiber/fiber
Latest Release: v2.52.8
about 1 year ago
Dependent Repos: 5,223
Dependent Packages: 5,791
Ranking: Top 0.1159% by dependent repos Top 0.0508% by dependent pkgs
PR Status
Open 550 (45.5%)
Merged 275 (22.7%)
Closed 293 (24.2%)
PR Types
Minor 70 (5.8%)
Patch 1,048 (86.7%)