CVE-2025-54801
HIGHDescription
Fiber is an Express inspired web framework written in Go. In versions 2.52.8 and below, when using Fiber's Ctx.BodyParser to parse form data containing a large numeric key that represents a slice index (e.g., test.18446744073704), the application crashes due to an out-of-bounds slice allocation in the underlying schema decoder. The root cause is that the decoder attempts to allocate a slice of length idx + 1 without validating whether the index is within a safe or reasonable range. If the idx is excessively large, this leads to an integer overflow or memory exhaustion, causing a panic or crash. This is fixed in version 2.52.9.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| gofiber | fiber |
References
Frequently Asked Questions
What is CVE-2025-54801? +
How severe is CVE-2025-54801? +
What products are affected by CVE-2025-54801? +
How do I check if I'm vulnerable to CVE-2025-54801? +
Related Vulnerabilities
Erlang is a programming language and runtime system for building massively scalable soft real-time systems with requirements on high availability. …
A vulnerability in the VPN and management web servers of the Cisco Adaptive Security Virtual Appliance (ASAv) and Cisco Secure …
Sticky Notes Widget 3.0.6 contains a denial of service vulnerability that allows attackers to crash the application by pasting excessively …
Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the remote read endpoint …
Color Notes 1.4 contains a denial of service vulnerability that allows attackers to crash the application by pasting excessively long …
memono Notepad 4.2 contains a denial of service vulnerability that allows attackers to crash the application by pasting excessively long …