Back

HIGH

Fiber Susceptible to Crash via `BodyParser` Due to Unvalidated Large Slice Index in Decoder

Published Aug 5, 2025

Description

Fiber is an Express inspired web framework written in Go. In versions 2.52.8 and below, when using Fiber's Ctx.BodyParser to parse form data containing a large numeric key that represents a slice index (e.g., test.18446744073704), the application crashes due to an out-of-bounds slice allocation in the underlying schema decoder. The root cause is that the decoder attempts to allocate a slice of length idx + 1 without validating whether the index is within a safe or reasonable range. If the idx is excessively large, this leads to an integer overflow or memory exhaustion, causing a panic or crash. This is fixed in version 2.52.9.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Aug 5, 2025
Updated Aug 7, 2025
Reserved Jul 29, 2025
CISA Vulnrichment
Updated Aug 7, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner GitHub_M
Published Aug 5, 2025
Updated Aug 7, 2025
Exploited since n/a
EUVD-2025-23668 GHSA-QX2Q-88MX-VHG7