<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 10:27:53 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-308590</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-308590</link>
      <description>EUVD-2026-308590</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-308590</guid>
    </item>
    <item>
      <title>fkie_cve-2026-30246</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-30246</link>
      <description>&lt;p&gt;Fiber is a web framework for Go. In github.com/gofiber/fiber/v3 versions through 3.1.0, the default key generator in the cache middleware uses only the request path and does not include the query string. As a result, requests for the same path with different query parameters can share a cache key and receive the wrong cached response. This can cause response mix-up for query-dependent endpoints and may expose data intended for a different request. This issue is fixed after version 3.1.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Fiber is a web framework for Go. In github.com/gofiber/fiber/v3 versions through 3.1.0, the default key generator in the cache middleware uses only the request path and does not include the query string. As a result, requests for the same path with different query parameters can share a cache key and receive the wrong cached response. This can cause response mix-up for query-dependent endpoints and may expose data intended for a different request. This issue is fixed after version 3.1.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-30246</guid>
    </item>
    <item>
      <title>GHSA-35hp-hqmv-8qg8 — Fiber's cache middleware default key generator ignores query string, causing response mix-up across distinct query para…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-35hp-hqmv-8qg8</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/gofiber/fiber/v3&lt;/p&gt;
&lt;p&gt;### Summary
Fiber cache middleware&amp;#39;s default key generator uses only `c.Path()` and does not include the query string.
As a result, requests like `/?id=1` and `/?id=2` can map to the same cache key and share the same cached response.&lt;/p&gt;
&lt;p&gt;This can cause response mix-up (cache poisoning-like behavior) for endpoints where response content depends on query parameters.&lt;/p&gt;
&lt;p&gt;### Details
Default configuration in cache middleware:&lt;/p&gt;
&lt;p&gt;- `KeyGenerator: func(c fiber.Ctx) string { return utils.CopyString(c.Path()) }`&lt;/p&gt;
&lt;p&gt;References:
- https://github.com/gofiber/fiber/blob/main/middleware/cache/config.go#L90-L92
- https://github.com/gofiber/fiber/blob/main/middleware/cache/cache_test.go#L599-L621&lt;/p&gt;
&lt;p&gt;The existing test demonstrates that when handler output depends on query parameter `id`, a second request with a different query still returns the first cached response (cache hit), confirming query is not part of the default cache key.&lt;/p&gt;
&lt;p&gt;### PoC
Minimal PoC:&lt;/p&gt;
&lt;p&gt;```go
package main&lt;/p&gt;
&lt;p&gt;import (
    &amp;#34;log&amp;#34;&lt;/p&gt;
&lt;p&gt;&amp;#34;github.com/gofiber/fiber/v3&amp;#34;
    &amp;#34;github.com/gofiber/fiber/v3/middleware/cache&amp;#34;
)&lt;/p&gt;
&lt;p&gt;func main() {
    app := fiber.New()
    app.Use(cache.New()) // default config&lt;/p&gt;
&lt;p&gt;app.Get(&amp;#34;/&amp;#34;, func(c fiber.Ctx) error {
        return c.SendString(c.Query(&amp;#34;id&amp;#34;, &amp;#34;1&amp;#34;))
    })&lt;/p&gt;
&lt;p&gt;log.Fatal(app.Listen(&amp;#34;:3000&amp;#34;))
}
```&lt;/p&gt;
&lt;p&gt;Reproduction:&lt;/p&gt;
&lt;p&gt;1. `GET /?id=1`
   - Cache miss
   - Response body: `1`
2. `GET /?id=2`
   - Cache hit
   - Response body: `1` (expected `2`)&lt;/p&gt;
&lt;p&gt;Local verification command used:&lt;/p&gt;
&lt;p&gt;```bash
go test ./middleware/ca…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/gofiber/fiber/v3&lt;/p&gt;
&lt;p&gt;### Summary
Fiber cache middleware&amp;#39;s default key generator uses only `c.Path()` and does not include the query string.
As a result, requests like `/?id=1` and `/?id=2` can map to the same cache key and share the same cached response.&lt;/p&gt;
&lt;p&gt;This can cause response mix-up (cache poisoning-like behavior) for endpoints where response content depends on query parameters.&lt;/p&gt;
&lt;p&gt;### Details
Default configuration in cache middleware:&lt;/p&gt;
&lt;p&gt;- `KeyGenerator: func(c fiber.Ctx) string { return utils.CopyString(c.Path()) }`&lt;/p&gt;
&lt;p&gt;References:
- https://github.com/gofiber/fiber/blob/main/middleware/cache/config.go#L90-L92
- https://github.com/gofiber/fiber/blob/main/middleware/cache/cache_test.go#L599-L621&lt;/p&gt;
&lt;p&gt;The existing test demonstrates that when handler output depends on query parameter `id`, a second request with a different query still returns the first cached response (cache hit), confirming query is not part of the default cache key.&lt;/p&gt;
&lt;p&gt;### PoC
Minimal PoC:&lt;/p&gt;
&lt;p&gt;```go
package main&lt;/p&gt;
&lt;p&gt;import (
    &amp;#34;log&amp;#34;&lt;/p&gt;
&lt;p&gt;&amp;#34;github.com/gofiber/fiber/v3&amp;#34;
    &amp;#34;github.com/gofiber/fiber/v3/middleware/cache&amp;#34;
)&lt;/p&gt;
&lt;p&gt;func main() {
    app := fiber.New()
    app.Use(cache.New()) // default config&lt;/p&gt;
&lt;p&gt;app.Get(&amp;#34;/&amp;#34;, func(c fiber.Ctx) error {
        return c.SendString(c.Query(&amp;#34;id&amp;#34;, &amp;#34;1&amp;#34;))
    })&lt;/p&gt;
&lt;p&gt;log.Fatal(app.Listen(&amp;#34;:3000&amp;#34;))
}
```&lt;/p&gt;
&lt;p&gt;Reproduction:&lt;/p&gt;
&lt;p&gt;1. `GET /?id=1`
   - Cache miss
   - Response body: `1`
2. `GET /?id=2`
   - Cache hit
   - Response body: `1` (expected `2`)&lt;/p&gt;
&lt;p&gt;Local verification command used:&lt;/p&gt;
&lt;p&gt;```bash
go test ./middleware/ca…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-35hp-hqmv-8qg8</guid>
    </item>
  </channel>
</rss>
