CVE-2026-53624
EUVD-2026-4235608.07.2026, 20:16
Fiber is an Express inspired web framework written in Go. Prior to 3.4.0, the helmet middleware in middleware/helmet/helmet.go never sets the Strict-Transport-Security response header even when HSTSMaxAge is configured because it checks c.Protocol() for https instead of c.Scheme(). This issue is fixed in version 3.4.0.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| gofiber | fiber | 𝑥 < 3.4.0 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Common Weakness Enumeration
References