CVE-2025-54801
Description
A flaw was found in github.com/gofiber/fiber/v2. The Ctx.BodyParser function fails to properly validate numeric form keys, allowing a large integer value to be interpreted as a slice index. This flaw allows a remote attacker to trigger this condition by submitting a crafted form with a sufficiently large numeric key. This issue leads to panic within the application, potentially resulting in a denial of service.
Statement
Red Hat Product Security has determined that this vulnerability does not affect any currently supported Red Hat product. This assessment may evolve based on further analysis and discovery. For more information about this vulnerability and the products it affects, please see the linked references.
Mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Understanding the Weakness (CWE)
Availability
Technical Impact: DoS: Resource Consumption (Memory)
Not controlling memory allocation can result in a request for too much system memory, possibly leading to a crash of the application due to out-of-memory conditions, or the consumption of a large amount of memory on the system.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.