CVE-2026-53624
Fiber is an Express inspired web framework written in Go. Prior to 3.4.0, the helmet middleware in middleware/helmet/helmet.go never sets the Strict-Transport-Security response header even when HSTSMaxAge is configured because it checks c.Protocol() for https instead of c.Scheme(). This issue is fixed in version 3.4.0.
Weakness
Fiber is an Express inspired web framework written in Go. Prior to 3.4.0, the helmet middleware in middleware/helmet/helmet.go never sets the Strict-Transport-Security response header even when HSTSMaxAge is configured because it checks c.Protocol() for https instead of c.Scheme(). This issue is fixed in version 3.4.0.
Affected products
- gofiber fiber
References
- https://github.com/gofiber/fiber/commit/04dd4e7754f61768fddccacc79057e416f13e6bf
- https://github.com/gofiber/fiber/pull/4389
- https://github.com/gofiber/fiber/releases/tag/v3.4.0
- https://github.com/gofiber/fiber/security/advisories/GHSA-gv83-gqw6-9j2c
- https://github.com/gofiber/fiber/security/advisories/GHSA-gv83-gqw6-9j2c
Find the bug before an attacker does.
Sign in with GitHub and run your first audit in under a minute. The free plan needs no credit card.