<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 03:56:48 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-240966</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-240966</link>
      <description>EUVD-2026-240966</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-240966</guid>
    </item>
    <item>
      <title>fkie_cve-2025-48075</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-48075</link>
      <description>&lt;p&gt;Fiber is an Express-inspired web framework written in Go. Starting in version 2.52.6 and prior to version 2.52.7, `fiber.Ctx.BodyParser` can map flat data to nested slices using `key[idx]value` syntax, but when idx is negative, it causes a panic instead of returning an error stating it cannot process the data. Since this data is user-provided, this could lead to denial of service for anyone relying on this `fiber.Ctx.BodyParser`  functionality. Version 2.52.7 fixes the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Fiber is an Express-inspired web framework written in Go. Starting in version 2.52.6 and prior to version 2.52.7, `fiber.Ctx.BodyParser` can map flat data to nested slices using `key[idx]value` syntax, but when idx is negative, it causes a panic instead of returning an error stating it cannot process the data. Since this data is user-provided, this could lead to denial of service for anyone relying on this `fiber.Ctx.BodyParser`  functionality. Version 2.52.7 fixes the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-48075</guid>
    </item>
    <item>
      <title>GHSA-hg3g-gphw-5hhm — Fiber panics when fiber.Ctx.BodyParser parses invalid range index</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hg3g-gphw-5hhm</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/gofiber/fiber/v2&lt;/p&gt;
&lt;p&gt;### Summary
When using the `fiber.Ctx.BodyParser` to parse into a struct with range values, a panic occurs when trying to parse a negative range index&lt;/p&gt;
&lt;p&gt;### Details
`fiber.Ctx.BodyParser` can map flat data to nested slices using `key[idx]value` syntax, however when idx is negative, it causes a panic instead of returning an error stating it cannot process the data.&lt;/p&gt;
&lt;p&gt;Since this data is user-provided, this could lead to denial of service for anyone relying on this `fiber.Ctx.BodyParser`  functionality&lt;/p&gt;
&lt;p&gt;### Reproducing
Take a simple GoFiberV2 server which returns a JSON encoded version of the FormData
```go
package main&lt;/p&gt;
&lt;p&gt;import (
	&amp;#34;encoding/json&amp;#34;
	&amp;#34;fmt&amp;#34;
	&amp;#34;net/http&amp;#34;&lt;/p&gt;
&lt;p&gt;&amp;#34;github.com/gofiber/fiber/v2&amp;#34;
)&lt;/p&gt;
&lt;p&gt;type RequestBody struct {
	NestedContent []*struct {
		Value string `form:&amp;#34;value&amp;#34;`
	} `form:&amp;#34;nested-content&amp;#34;`
}&lt;/p&gt;
&lt;p&gt;func main() {
	app := fiber.New()&lt;/p&gt;
&lt;p&gt;app.Post(&amp;#34;/&amp;#34;, func(c *fiber.Ctx) error {
		formData := RequestBody{}
		if err := c.BodyParser(&amp;amp;formData); err != nil {
			fmt.Println(err)
			return c.SendStatus(http.StatusUnprocessableEntity)
		}
                c.Set(&amp;#34;Content-Type&amp;#34;, &amp;#34;application/json&amp;#34;)
                s, _ := json.Marshal(formData)
                return c.SendString(string(s))
	})&lt;/p&gt;
&lt;p&gt;fmt.Println(app.Listen(&amp;#34;:3000&amp;#34;))
}&lt;/p&gt;
&lt;p&gt;```&lt;/p&gt;
&lt;p&gt;**Correct Behaviour**
Send a valid request such as:
```bash
curl --location &amp;#39;localhost:3000&amp;#39; \
--form &amp;#39;nested-content[0].value=&amp;#34;Foo&amp;#34;&amp;#39; \
--form &amp;#39;nested-content[1].value=&amp;#34;Bar&amp;#34;&amp;#39;
```
You recieve valid JSON
```json
{&amp;#34;NestedContent&amp;#34;:[{&amp;#34;Value&amp;#34;:&amp;#34;Foo&amp;#34;},{&amp;#34;…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/gofiber/fiber/v2&lt;/p&gt;
&lt;p&gt;### Summary
When using the `fiber.Ctx.BodyParser` to parse into a struct with range values, a panic occurs when trying to parse a negative range index&lt;/p&gt;
&lt;p&gt;### Details
`fiber.Ctx.BodyParser` can map flat data to nested slices using `key[idx]value` syntax, however when idx is negative, it causes a panic instead of returning an error stating it cannot process the data.&lt;/p&gt;
&lt;p&gt;Since this data is user-provided, this could lead to denial of service for anyone relying on this `fiber.Ctx.BodyParser`  functionality&lt;/p&gt;
&lt;p&gt;### Reproducing
Take a simple GoFiberV2 server which returns a JSON encoded version of the FormData
```go
package main&lt;/p&gt;
&lt;p&gt;import (
	&amp;#34;encoding/json&amp;#34;
	&amp;#34;fmt&amp;#34;
	&amp;#34;net/http&amp;#34;&lt;/p&gt;
&lt;p&gt;&amp;#34;github.com/gofiber/fiber/v2&amp;#34;
)&lt;/p&gt;
&lt;p&gt;type RequestBody struct {
	NestedContent []*struct {
		Value string `form:&amp;#34;value&amp;#34;`
	} `form:&amp;#34;nested-content&amp;#34;`
}&lt;/p&gt;
&lt;p&gt;func main() {
	app := fiber.New()&lt;/p&gt;
&lt;p&gt;app.Post(&amp;#34;/&amp;#34;, func(c *fiber.Ctx) error {
		formData := RequestBody{}
		if err := c.BodyParser(&amp;amp;formData); err != nil {
			fmt.Println(err)
			return c.SendStatus(http.StatusUnprocessableEntity)
		}
                c.Set(&amp;#34;Content-Type&amp;#34;, &amp;#34;application/json&amp;#34;)
                s, _ := json.Marshal(formData)
                return c.SendString(string(s))
	})&lt;/p&gt;
&lt;p&gt;fmt.Println(app.Listen(&amp;#34;:3000&amp;#34;))
}&lt;/p&gt;
&lt;p&gt;```&lt;/p&gt;
&lt;p&gt;**Correct Behaviour**
Send a valid request such as:
```bash
curl --location &amp;#39;localhost:3000&amp;#39; \
--form &amp;#39;nested-content[0].value=&amp;#34;Foo&amp;#34;&amp;#39; \
--form &amp;#39;nested-content[1].value=&amp;#34;Bar&amp;#34;&amp;#39;
```
You recieve valid JSON
```json
{&amp;#34;NestedContent&amp;#34;:[{&amp;#34;Value&amp;#34;:&amp;#34;Foo&amp;#34;},{&amp;#34;…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hg3g-gphw-5hhm</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15179-1 — govulncheck-vulndb-0.0.20250527T204717-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15179-1</link>
      <description>&lt;p&gt;govulncheck-vulndb-0.0.20250527T204717-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;govulncheck-vulndb-0.0.20250527T204717-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15179-1</guid>
    </item>
  </channel>
</rss>
