CVE-2026-45045: Gofiber Fiber
Medium severity, CVSS 5.3. EPSS: 0.5% chance of exploitation in the next 30 days.
Fiber is an Express inspired web framework written in Go. Prior to 3.3.0 and 2.52.14, the BalancerForward proxy helper in middleware/proxy/proxy.go uses Header.Add() instead of Header.Set() when injecting X-Real-IP, allowing an attacker-supplied first X-Real-IP value to be forwarded to upstream servers for logging, rate limiting, and access control. This issue is fixed in version 3.3.0 and 2.52.14.
Affected products
- Gofiber Fiber: before 2.52.14 (fixed in 2.52.14); from 3.0.0, before 3.3.0 (fixed in 3.3.0)
Published 2026-07-08. Last modified 2026-07-15.