CVE-2026-44332
published 2026-07-08CVE-2026-44332: Fiber is an Express inspired web framework written in Go. Prior to 3.3.0, the default Authorizer function in the BasicAuth middleware in…
PriorityP431medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
0.52%
43.0th percentile
Fiber is an Express inspired web framework written in Go. Prior to 3.3.0, the default Authorizer function in the BasicAuth middleware in middleware/basicauth/config.go uses short-circuit evaluation that skips password hash comparison for non-existent usernames, enabling reliable remote username enumeration through response timing differences. This issue is fixed in version 3.3.0.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | gofiber_fiber_v3 | >= 0 < 3.3.0 | 3.3.0 |
| gofiber | fiber | < 3.3.0 | 3.3.0 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
gofiber up to 3.1.0 BasicAuth Default Authorizer information exposure
vuldb·2026-07-13·CVSS 5.3
CVE-2026-44332 [MEDIUM] gofiber up to 3.1.0 BasicAuth Default Authorizer information exposure
A vulnerability classified as problematic was found in gofiber fiber up to 3.1.0. Affected by this issue is some unknown functionality of the component BasicAuth Default Authorizer. Executing a manipulation can lead to information exposure through discrepancy.
This vulnerability is tracked as CVE-2026-44332. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is advised.
GHSA
GoFiber Vulnerable to Username Enumeration via Timing Oracle in BasicAuth Default Authorizer
ghsa·2026-07-02
CVE-2026-44332 [MEDIUM] CWE-203 GoFiber Vulnerable to Username Enumeration via Timing Oracle in BasicAuth Default Authorizer
GoFiber Vulnerable to Username Enumeration via Timing Oracle in BasicAuth Default Authorizer
## Summary
The default `Authorizer` function in GoFiber's BasicAuth middleware uses short-circuit evaluation that skips password hash comparison for non-existent usernames. With bcrypt-hashed passwords (the primary use case), the timing difference between a valid and invalid username is approximately 1,000,000:1 (~100ms vs ~100ns), enabling reliable remote username enumeration.
## Vulnerable Code
**File:** `middleware/basicauth/config.go`, lines 126-138
```go
if cfg.Authorizer == nil {
verifiers := make(map[string]func(string) bool, len(cfg.Users))
for u, hpw := range cfg.Users {
v, err := parseHashedPassword(hpw)
if err != nil {
panic(err)
}
verifiers[u] = v
}
cfg.Authorizer = func(user, pass
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-44332 golang-github-gofiber-fiber-2: GoFiber: Remote Username Enumeration via BasicAuth Middleware Short-Circuit Evaluation [fedora-all]
bugzilla·2026-07-09·CVSS 5.3
CVE-2026-44332 [MEDIUM] CVE-2026-44332 golang-github-gofiber-fiber-2: GoFiber: Remote Username Enumeration via BasicAuth Middleware Short-Circuit Evaluation [fedora-all]
CVE-2026-44332 golang-github-gofiber-fiber-2: GoFiber: Remote Username Enumeration via BasicAuth Middleware Short-Circuit Evaluation [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Fiber is an Express inspired web framework written in Go. Prior to 3.3.0, the default Authorizer function in the BasicAuth middleware in middleware/basicauth/config.go uses short-circuit evaluation that skips password hash comparison for non-existent usernames, enabling reliable remote username enumeration through response timing differences. This issue is fixed in version 3.3.0.
Bugzilla
CVE-2026-44332 github.com/gofiber/fiber: GoFiber: Remote Username Enumeration via BasicAuth Middleware Short-Circuit Evaluation
bugzilla·2026-07-08·CVSS 5.3
CVE-2026-44332 [MEDIUM] CVE-2026-44332 github.com/gofiber/fiber: GoFiber: Remote Username Enumeration via BasicAuth Middleware Short-Circuit Evaluation
CVE-2026-44332 github.com/gofiber/fiber: GoFiber: Remote Username Enumeration via BasicAuth Middleware Short-Circuit Evaluation
Fiber is an Express inspired web framework written in Go. Prior to 3.3.0, the default Authorizer function in the BasicAuth middleware in middleware/basicauth/config.go uses short-circuit evaluation that skips password hash comparison for non-existent usernames, enabling reliable remote username enumeration through response timing differences. This issue is fixed in version 3.3.0.
2026-07-08
Published