Cleartext Transmission of Sensitive Information Affecting github.com/gofiber/fiber/v3/middleware/helmet package, versions <3.4.0


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.21% (12th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-GITHUBCOMGOFIBERFIBERV3MIDDLEWAREHELMET-17857562
  • published7 Jul 2026
  • disclosed6 Jul 2026
  • creditUnknown

Introduced: 6 Jul 2026

CVE-2026-53624  (opens in a new tab)
CWE-319  (opens in a new tab)

How to fix?

Upgrade github.com/gofiber/fiber/v3/middleware/helmet to version 3.4.0 or higher.

Overview

Affected versions of this package are vulnerable to Cleartext Transmission of Sensitive Information due to the incorrect protocol check in the helmet middleware, which fails to set the Strict-Transport-Security header even when configured. An attacker can intercept and manipulate network traffic by performing SSL stripping or protocol downgrade attacks, potentially exposing sensitive information or session cookies over unsecured HTTP connections.

CVSS Base Scores

version 4.0
version 3.1