CVE-2025-54801
Description
Fiber is an Express inspired web framework written in Go. In versions 2.52.8 and below, when using Fiber's Ctx.BodyParser to parse form data containing a large numeric key that represents a slice index (e.g., test.18446744073704), the application crashes due to an out-of-bounds slice allocation in the underlying schema decoder. The root cause is that the decoder attempts to allocate a slice of length idx + 1 without validating whether the index is within a safe or reasonable range. If the idx is excessively large, this leads to an integer overflow or memory exhaustion, causing a panic or crash. This is fixed in version 2.52.9.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/gofiber/fiber/v2Go | < 2.52.9 | 2.52.9 |
Affected products
10- osv-coords8 versionspkg:apk/chainguard/gatuspkg:apk/chainguard/gatus-compatpkg:apk/wolfi/gatuspkg:apk/wolfi/gatus-compatpkg:golang/github.com/gofiber/fiber/v2pkg:rpm/opensuse/govulncheck-vulndb&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/govulncheck-vulndb&distro=openSUSE%20Tumbleweedpkg:rpm/suse/govulncheck-vulndb&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP6
< 5.21.0-r1+ 7 more
- (no CPE)range: < 5.21.0-r1
- (no CPE)range: < 5.21.0-r1
- (no CPE)range: < 5.21.0-r1
- (no CPE)range: < 5.21.0-r1
- (no CPE)range: < 2.52.9
- (no CPE)range: < 0.0.20250814T182633-150000.1.98.1
- (no CPE)range: < 0.0.20250811T192933-1.1
- (no CPE)range: < 0.0.20250814T182633-150000.1.98.1
Patches
Vulnerability mechanics
References
4- github.com/gofiber/fiber/commit/e115c08b8f059a4a031b492aa9eef0712411853dnvdPatchWEB
- github.com/advisories/GHSA-qx2q-88mx-vhg7ghsaADVISORY
- github.com/gofiber/fiber/security/advisories/GHSA-qx2q-88mx-vhg7nvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2025-54801ghsaADVISORY
News mentions
0No linked articles in our index yet.