cbcvebase.
CVE-2026-45045
published 2026-07-08

CVE-2026-45045: Fiber is an Express inspired web framework written in Go. Prior to 3.3.0 and 2.52.14, the BalancerForward proxy helper in middleware/proxy/proxy.go uses…

PriorityP430medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
0.46%
39.4th percentile
Fiber is an Express inspired web framework written in Go. Prior to 3.3.0 and 2.52.14, the BalancerForward proxy helper in middleware/proxy/proxy.go uses Header.Add() instead of Header.Set() when injecting X-Real-IP, allowing an attacker-supplied first X-Real-IP value to be forwarded to upstream servers for logging, rate limiting, and access control. This issue is fixed in version 3.3.0 and 2.52.14.

Affected

5 ranges
VendorProductVersion rangeFixed in
github.comgofiber_fiber_v20 – 2.52.13—
github.comgofiber_fiber_v3>= 0 < 3.3.03.3.0
gofiberfiber< 2.52.142.52.14
gofiberfiber——
gofiberfiber>= 3.0.0 < 3.3.03.3.0
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.