CVE-2026-53624
published 2026-07-08CVE-2026-53624: Fiber is an Express inspired web framework written in Go. Prior to 3.4.0, the helmet middleware in middleware/helmet/helmet.go never sets the…
PriorityP423medium4.8CVSS 3.1
AVNACHPRNUINSUCLILAN
EPSS
0.21%
11.8th percentile
Fiber is an Express inspired web framework written in Go. Prior to 3.4.0, the helmet middleware in middleware/helmet/helmet.go never sets the Strict-Transport-Security response header even when HSTSMaxAge is configured because it checks c.Protocol() for https instead of c.Scheme(). This issue is fixed in version 3.4.0.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | gofiber_fiber | >= 0 < 3.4.0 | 3.4.0 |
| gofiber | fiber | < 3.4.0 | 3.4.0 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
gofiber Fiber up to 3.3.x Helmet Middleware helmet.go c.Protocol missing encryption
vuldb·2026-07-13·CVSS 4.8
CVE-2026-53624 [MEDIUM] gofiber Fiber up to 3.3.x Helmet Middleware helmet.go c.Protocol missing encryption
A vulnerability, which was classified as problematic, has been found in gofiber Fiber up to 3.3.x. The affected element is the function c.Protocol of the file middleware/helmet/helmet.go of the component Helmet Middleware. Performing a manipulation results in missing encryption of sensitive data.
This vulnerability is known as CVE-2026-53624. Remote exploitation of the attack is possible. No exploit is available.
GHSA
GoFiber never set HSTS header in helmet middleware due to incorrect protocol check
ghsa·2026-07-06
CVE-2026-53624 [MEDIUM] CWE-319 GoFiber never set HSTS header in helmet middleware due to incorrect protocol check
GoFiber never set HSTS header in helmet middleware due to incorrect protocol check
### Summary
The `helmet` middleware in gofiber/fiber never sets the `Strict-Transport-Security` (HSTS) response header, even when `HSTSMaxAge` is explicitly configured, because the condition check at `helmet.go:67` uses `c.Protocol()` — which returns the HTTP protocol version string (e.g., `"HTTP/1.1"`, `"HTTP/2.0"`) — instead of `c.Scheme()` — which returns the URL scheme (`"http"` or `"https"`). Since `c.Protocol()` never equals `"https"` in any real deployment, the HSTS header is permanently disabled, defeating the security protection.
### Details
**Root cause:** `middleware/helmet/helmet.go`, line 67:
```go
if c.Protocol() == "https" && cfg.HSTSMaxAge != 0 {
```
`c.Protocol()` (defined at `req.go:8
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-53624 golang-github-gofiber-fiber-2: Fiber web framework: Information disclosure due to incorrect HTTPS protocol check in helmet middleware [fedora-all]
bugzilla·2026-08-24·CVSS 4.8
CVE-2026-53624 [MEDIUM] CVE-2026-53624 golang-github-gofiber-fiber-2: Fiber web framework: Information disclosure due to incorrect HTTPS protocol check in helmet middleware [fedora-all]
CVE-2026-53624 golang-github-gofiber-fiber-2: Fiber web framework: Information disclosure due to incorrect HTTPS protocol check in helmet middleware [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Fiber is an Express inspired web framework written in Go. Prior to 3.4.0, the helmet middleware in middleware/helmet/helmet.go never sets the Strict-Transport-Security response header even when HSTSMaxAge is configured because it checks c.Protocol() for https instead of c.Scheme(). This issue is fixed in version 3.4.0.
Bugzilla
CVE-2026-53624 github.com/gofiber/fiber: Fiber web framework: Information disclosure due to incorrect HTTPS protocol check in helmet middleware
bugzilla·2026-07-08·CVSS 4.8
CVE-2026-53624 [MEDIUM] CVE-2026-53624 github.com/gofiber/fiber: Fiber web framework: Information disclosure due to incorrect HTTPS protocol check in helmet middleware
CVE-2026-53624 github.com/gofiber/fiber: Fiber web framework: Information disclosure due to incorrect HTTPS protocol check in helmet middleware
Fiber is an Express inspired web framework written in Go. Prior to 3.4.0, the helmet middleware in middleware/helmet/helmet.go never sets the Strict-Transport-Security response header even when HSTSMaxAge is configured because it checks c.Protocol() for https instead of c.Scheme(). This issue is fixed in version 3.4.0.
https://github.com/gofiber/fiber/commit/04dd4e7754f61768fddccacc79057e416f13e6bfhttps://github.com/gofiber/fiber/pull/4389https://github.com/gofiber/fiber/releases/tag/v3.4.0https://github.com/gofiber/fiber/security/advisories/GHSA-gv83-gqw6-9j2chttps://github.com/gofiber/fiber/security/advisories/GHSA-gv83-gqw6-9j2c
2026-07-08
Published