Vulnerability Report: GO-2026-5887
- CVE-2026-45045, GHSA-gcfq-8gqf-4876
- Affects: github.com/gofiber/fiber/v3
- Published: Jul 24, 2026
GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward in github.com/gofiber/fiber
For detailed information about this vulnerability, visit https://github.com/gofiber/fiber/security/advisories/GHSA-gcfq-8gqf-4876.
Affected Packages
-
PathGo VersionsSymbols
-
before v3.3.0
Aliases
References
- https://github.com/gofiber/fiber/security/advisories/GHSA-gcfq-8gqf-4876
- https://github.com/gofiber/fiber/pull/4260
- https://vuln.go.dev/ID/GO-2026-5887.json
Feedback
See anything missing or incorrect?
Suggest an edit to this report.