CVE-2026-25899 - Vulnerability Analysis
HighCVSS: 7.5Last Updated: February 25, 2026
Fiber - Denial of Service
Overview
Fiber v3 < 3.1.0 contains an insecure deserialization vulnerability caused by unvalidated msgpack deserialization of the fiber_flash cookie, letting remote attackers cause unbounded memory allocation, exploit requires no authentication.
Severity & Score
Impact
Remote attackers can cause unbounded memory allocation, leading to denial of service by exhausting server resources.
Mitigation
Upgrade to version 3.1.0 or later.
References
Social Media Activity(2 posts)
š CVE-2026-25899 - High (7.5) Fiber is an Express inspired web framework written in Go. In versions on the v3 branch prior to 3.1.0, the use of the `fiber_flash` cookie can force an unbounded allocation on any server. A crafted 10-character cookie value triggers an attempt to ... š https://www.thehackerwire.com/vulnerability/CVE-2026-25899/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
View original postš CVE-2026-25899 - High (7.5) Fiber is an Express inspired web framework written in Go. In versions on the v3 branch prior to 3.1.0, the use of the `fiber_flash` cookie can force an unbounded allocation on any server. A crafted 10-character cookie value triggers an attempt to ... š https://www.thehackerwire.com/vulnerability/CVE-2026-25899/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
View original postRelated Resources
Details
- CVE ID
- CVE-2026-25899
- Severity
- High
- CVSS Score
- 7.5
- Type
- insecure_deserialization
- Status
- confirmed
- EPSS
- 0.0%
- Social Posts
- 2
CWE
- CWE-789
- CWE-770
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H