—
GO-2026-5886
GoFiber Vulnerable to Username Enumeration via Timing Oracle in BasicAuth Default Authorizer in github.com/gofiber/fiber
Quick fix
GO-2026-5886 — github.com/gofiber/fiber/v3: upgrade to the fixed version with the command below.
go get github.com/gofiber/fiber/v3@v3.3.0 Details
GoFiber Vulnerable to Username Enumeration via Timing Oracle in BasicAuth Default Authorizer in github.com/gofiber/fiber
Are you affected?
Enter the version of the package you're using.
Affected packages
Go / github.com/gofiber/fiber/v3
Introduced in:
0 Fixed in: 3.3.0 Fix
go get github.com/gofiber/fiber/v3@v3.3.0