CVE-2025-54801
Last modified
CVE-2025-54801 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Fiber is an Express inspired web framework written in Go. In versions 2.52.8 and below, when using Fiber's Ctx.BodyParser to parse form data containing a large numeric key that represents a slice index (e.g., test.18446744073704), the application crashes due to an out-of-bounds slice allocation in the underlying schema decoder. EPSS estimates a 0.33% chance of exploitation in the next 30 days.
Description
Fiber is an Express inspired web framework written in Go. In versions 2.52.8 and below, when using Fiber's Ctx.BodyParser to parse form data containing a large numeric key that represents a slice index (e.g., test.18446744073704), the application crashes due to an out-of-bounds slice allocation in the underlying schema decoder. The root cause is that the decoder attempts to allocate a slice of length idx + 1 without validating whether the index is within a safe or reasonable range. If the idx is excessively large, this leads to an integer overflow or memory exhaustion, causing a panic or crash. This is fixed in version 2.52.9.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gofiber | Fiber | < 2.52.9 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-54801?
How severe is CVE-2025-54801?
How do I fix CVE-2025-54801?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-54796Copyparty is a portable file server. Versions prior to 1.18.…7.5
- CVE-2025-54797Rejected reason: This CVE is a duplicate of CVE-2025-52464.
- CVE-2025-54798tmp is a temporary file and directory creator for node.js. I…5.3
- CVE-2025-54799Let's Encrypt client and ACME library written in Go (Lego). …2.3
- CVE-2025-5480Action1 Uncontrolled Search Path Element Local Privilege Esc…7.8
- CVE-2025-54800Hydra is a continuous integration service for Nix based proj…6.1
- CVE-2025-54802pyLoad is the free and open-source Download Manager written …9.8
- CVE-2025-54803js-toml is a TOML parser for JavaScript, fully compliant wit…7.5
- CVE-2025-54804Russh is a Rust SSH client & server library. In versions 0.5…6.5
- CVE-2025-54805When an iRule is configured on a virtual server via the decl…6.5
- CVE-2025-54806GROWI v4.2.7 and earlier contains a cross-site scripting vul…6.1
- CVE-2025-54807The secret used for validating authentication tokens is hard…9.8
Are you affected by CVE-2025-54801?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
