CVE-2025-54801 - CVE House
Back to Database
Status published High CVE-2025-54801

Fiber Susceptible to Crash via `BodyParser` Due to Unvalidated Large Slice Index in Decoder

Vulnerability Description

Fiber is an Express inspired web framework written in Go. In versions 2.52.8 and below, when using Fiber's Ctx.BodyParser to parse form data containing a large numeric key that represents a slice index (e.g., test.18446744073704), the application crashes due to an out-of-bounds slice allocation in the underlying schema decoder. The root cause is that the decoder attempts to allocate a slice of length idx + 1 without validating whether the index is within a safe or reasonable range. If the idx is excessively large, this leads to an integer overflow or memory exhaustion, causing a panic or crash. This is fixed in version 2.52.9.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-54801

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

fiber
Vulnerable Versions:
< 2.52.9

Timeline

Official Publish: August 5th, 2025
Last Modified: August 7th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.