<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 11:27:57 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-335641</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-335641</link>
      <description>EUVD-2026-335641</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-335641</guid>
    </item>
    <item>
      <title>fkie_cve-2026-53624</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-53624</link>
      <description>&lt;p&gt;Fiber is an Express inspired web framework written in Go. Prior to 3.4.0, the helmet middleware in middleware/helmet/helmet.go never sets the Strict-Transport-Security response header even when HSTSMaxAge is configured because it checks c.Protocol() for https instead of c.Scheme(). This issue is fixed in version 3.4.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Fiber is an Express inspired web framework written in Go. Prior to 3.4.0, the helmet middleware in middleware/helmet/helmet.go never sets the Strict-Transport-Security response header even when HSTSMaxAge is configured because it checks c.Protocol() for https instead of c.Scheme(). This issue is fixed in version 3.4.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-53624</guid>
    </item>
    <item>
      <title>GHSA-gv83-gqw6-9j2c — GoFiber never set HSTS header in helmet middleware due to incorrect protocol check</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-gv83-gqw6-9j2c</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/gofiber/fiber&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The `helmet` middleware in gofiber/fiber never sets the `Strict-Transport-Security` (HSTS) response header, even when `HSTSMaxAge` is explicitly configured, because the condition check at `helmet.go:67` uses `c.Protocol()` — which returns the HTTP protocol version string (e.g., `&amp;#34;HTTP/1.1&amp;#34;`, `&amp;#34;HTTP/2.0&amp;#34;`) — instead of `c.Scheme()` — which returns the URL scheme (`&amp;#34;http&amp;#34;` or `&amp;#34;https&amp;#34;`). Since `c.Protocol()` never equals `&amp;#34;https&amp;#34;` in any real deployment, the HSTS header is permanently disabled, defeating the security protection.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;**Root cause:** `middleware/helmet/helmet.go`, line 67:&lt;/p&gt;
&lt;p&gt;```go
if c.Protocol() == &amp;#34;https&amp;#34; &amp;amp;&amp;amp; cfg.HSTSMaxAge != 0 {
```&lt;/p&gt;
&lt;p&gt;`c.Protocol()` (defined at `req.go:865-867`) delegates to `fasthttp.Request.Header.Protocol()`, which returns the HTTP protocol version:
- `&amp;#34;HTTP/1.1&amp;#34;` for HTTP/1.1 connections
- `&amp;#34;HTTP/2.0&amp;#34;` for HTTP/2 connections&lt;/p&gt;
&lt;p&gt;The correct method is `c.Scheme()` (defined at `req.go:844-862`), which returns:
- `&amp;#34;http&amp;#34;` for plain HTTP connections
- `&amp;#34;https&amp;#34;` for TLS connections&lt;/p&gt;
&lt;p&gt;Since `&amp;#34;HTTP/1.1&amp;#34; != &amp;#34;https&amp;#34;` always evaluates to `true`, the entire HSTS block (lines 67-76) is dead code.&lt;/p&gt;
&lt;p&gt;**Note on test coverage:** The existing helmet test (`helmet_test.go`) passes because it uses `ctx.Request.Header.SetProtocol(&amp;#34;https&amp;#34;)` to artificially force `Protocol()` to return `&amp;#34;https&amp;#34;`. However, `fasthttp.Request.Header.SetProtocol()` sets the HTTP version field, and real HTTP requests never have protocol `&amp;#34;https&amp;#34;` — they have `&amp;#34;HTTP/…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/gofiber/fiber&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The `helmet` middleware in gofiber/fiber never sets the `Strict-Transport-Security` (HSTS) response header, even when `HSTSMaxAge` is explicitly configured, because the condition check at `helmet.go:67` uses `c.Protocol()` — which returns the HTTP protocol version string (e.g., `&amp;#34;HTTP/1.1&amp;#34;`, `&amp;#34;HTTP/2.0&amp;#34;`) — instead of `c.Scheme()` — which returns the URL scheme (`&amp;#34;http&amp;#34;` or `&amp;#34;https&amp;#34;`). Since `c.Protocol()` never equals `&amp;#34;https&amp;#34;` in any real deployment, the HSTS header is permanently disabled, defeating the security protection.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;**Root cause:** `middleware/helmet/helmet.go`, line 67:&lt;/p&gt;
&lt;p&gt;```go
if c.Protocol() == &amp;#34;https&amp;#34; &amp;amp;&amp;amp; cfg.HSTSMaxAge != 0 {
```&lt;/p&gt;
&lt;p&gt;`c.Protocol()` (defined at `req.go:865-867`) delegates to `fasthttp.Request.Header.Protocol()`, which returns the HTTP protocol version:
- `&amp;#34;HTTP/1.1&amp;#34;` for HTTP/1.1 connections
- `&amp;#34;HTTP/2.0&amp;#34;` for HTTP/2 connections&lt;/p&gt;
&lt;p&gt;The correct method is `c.Scheme()` (defined at `req.go:844-862`), which returns:
- `&amp;#34;http&amp;#34;` for plain HTTP connections
- `&amp;#34;https&amp;#34;` for TLS connections&lt;/p&gt;
&lt;p&gt;Since `&amp;#34;HTTP/1.1&amp;#34; != &amp;#34;https&amp;#34;` always evaluates to `true`, the entire HSTS block (lines 67-76) is dead code.&lt;/p&gt;
&lt;p&gt;**Note on test coverage:** The existing helmet test (`helmet_test.go`) passes because it uses `ctx.Request.Header.SetProtocol(&amp;#34;https&amp;#34;)` to artificially force `Protocol()` to return `&amp;#34;https&amp;#34;`. However, `fasthttp.Request.Header.SetProtocol()` sets the HTTP version field, and real HTTP requests never have protocol `&amp;#34;https&amp;#34;` — they have `&amp;#34;HTTP/…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-gv83-gqw6-9j2c</guid>
    </item>
  </channel>
</rss>
