Medium severity5.3NVD Advisory· Published Jul 8, 2026· Updated Jul 15, 2026
CVE-2026-45045
CVE-2026-45045
Description
Fiber is an Express inspired web framework written in Go. Prior to 3.3.0 and 2.52.14, the BalancerForward proxy helper in middleware/proxy/proxy.go uses Header.Add() instead of Header.Set() when injecting X-Real-IP, allowing an attacker-supplied first X-Real-IP value to be forwarded to upstream servers for logging, rate limiting, and access control. This issue is fixed in version 3.3.0 and 2.52.14.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/gofiber/fiber/v3Go | < 3.3.0 | 3.3.0 |
github.com/gofiber/fiber/v2Go | < 2.52.14 | 2.52.14 |
Affected products
5- osv-coords3 versionspkg:apk/wolfi/gatuspkg:apk/chainguard/gatuspkg:rpm/opensuse/govulncheck-vulndb&distro=openSUSE%20Leap%2016.0
< 5.36.0-r8+ 2 more
- (no CPE)range: < 5.36.0-r8
- (no CPE)range: < 5.36.0-r8
- (no CPE)range: < 0.0.20260727T201416-160000.1.1
Patches
Vulnerability mechanics
References
9- github.com/gofiber/fiber/commit/1403cc8292da3220e9316960b4030cc722a0f396nvdPatchWEB
- github.com/gofiber/fiber/commit/33c9501288ab47a429c8b5e701493f0c3c0af37dnvdPatchWEB
- github.com/gofiber/fiber/pull/4260nvdIssue TrackingPatchWEB
- github.com/gofiber/fiber/pull/4495nvdIssue TrackingPatchWEB
- github.com/gofiber/fiber/security/advisories/GHSA-gcfq-8gqf-4876nvdExploitVendor AdvisoryWEB
- github.com/advisories/GHSA-gcfq-8gqf-4876ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-45045ghsaADVISORY
- github.com/gofiber/fiber/releases/tag/v2.52.14nvdRelease NotesWEB
- github.com/gofiber/fiber/releases/tag/v3.3.0nvdRelease NotesWEB
News mentions
0No linked articles in our index yet.