{"id":"CVE-2025-66630","aliases":["GHSA-68rr-p4fp-j59v","GO-2026-4471"],"title":"Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() — predictable / zero‑UUID on crypto/rand failure","summary":"Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() — predictable / zero‑UUID on crypto/rand failure","severity":"critical","vendor":"gofiber","product":"github.com/gofiber/fiber/v2","ecosystem":"go","affected":["github.com/gofiber/fiber/v2 < 2.52.11"],"patched":["github.com/gofiber/fiber/v2 2.52.11"],"published":"2026-02-09","updated":"2026-09-10","sourceUpdated":"2026-09-10T03:49:54.322457183Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-68rr-p4fp-j59v","references":[{"url":"https://github.com/gofiber/fiber/security/advisories/GHSA-68rr-p4fp-j59v"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-66630"},{"url":"https://github.com/gofiber/fiber/commit/eb874b6f6c5896b968d9b0ab2b56ac7052cb0ee1"},{"url":"https://github.com/gofiber/fiber"},{"url":"https://github.com/gofiber/fiber/releases/tag/v2.52.11"}],"tags":["osv","go"],"epss":0.00489,"epssPercentile":0.41199,"ingestedAt":"2026-09-12T03:13:01.758Z","slug":"CVE-2025-66630","body":"## Overview\n\nFiber v2 contains an internal vendored copy of `gofiber/utils`, and its functions `UUIDv4()` and `UUID()` inherit the same critical weakness described in the upstream advisory. On **Go versions prior to 1.24**, the underlying `crypto/rand` implementation **can return an error** if secure randomness cannot be obtained. In such cases, these Fiber v2 UUID functions silently fall back to generating predictable values — the all-zero UUID `00000000-0000-0000-0000-000000000000`.\n\nOn Go **1.24+**, the language guarantees that `crypto/rand` no longer returns an error (it will block or panic instead), so this vulnerability primarily affects **Fiber v2 users running Go 1.23 or earlier**, which Fiber v2 officially supports.\n\nBecause no error is returned by the Fiber v2 UUID functions, application code may unknowingly rely on *predictable, repeated, or low-entropy identifiers* in security-critical pathways. This is especially impactful because many Fiber v2 middleware components (session middleware, CSRF, rate limiting, request-ID generation, etc.) **default to using `utils.UUIDv4()`**.\n\nImpact includes, but is not limited to:\n\n* **Session fixation or hijacking** (predictable session IDs)\n* **CSRF token forgery** or bypass\n* **Authentication replay / token prediction**\n* **Potential denial-of-service (DoS):** if the zero UUID is generated, key-based structures (sessions, rate-limits, caches, CSRF stores) may collapse into a single shared key, causing overwrites, lock contention, or state corruption\n* **Request-ID collisions**, undermining logging and trace integrity\n* **General compromise** of confidentiality, integrity, and authorization logic relying on UUIDs for uniqueness or secrecy\n\nAll Fiber v2 versions containing the internal `utils.UUIDv4()` / `utils.UUID()` implementation are affected when running on **Go <1.24**. **No patched Fiber v2 release currently exists.**\n\n---\n\n## Suggested Mitigations / Workarounds\n\nUpdate to the latest version of Fiber v2.\n\n---\n\n### Likelihood / Environmental Factors\n\nIt’s important to note that **entropy exhaustion on modern Linux systems is extremely rare**, as the kernel’s CSPRNG is resilient and non-blocking. However, **entropy-source failures** — where `crypto/rand` cannot read from its underlying provider — are significantly more likely in certain environments.\n\nThis includes containerized deployments, restricted sandboxes, misconfigured systems lacking read access to `/dev/urandom` or platform-equivalent sources, chrooted or jailed environments, embedded devices, or systems with non-standard or degraded randomness providers. On **Go <1.24**, such failures cause `crypto/rand` to return an error, which the Fiber v2 UUID functions currently treat as a signal to silently generate predictable UUIDs, including the zero UUID. This silent fallback is the root cause of the vulnerability.\n\n---\n\n## References\n\n* Upstream advisory for `gofiber/utils`: **GHSA-m98w-cqp3-qcqr**\n* Source repositories:\n\n  * `github.com/gofiber/fiber`\n  * `github.com/gofiber/utils`\n\n---\n\n## Credits / Reporter\n\nReported by **@sixcolors** (Fiber Maintainer / Security Team)\n\n## Affected packages\n\n- `github.com/gofiber/fiber/v2 < 2.52.11`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `github.com/gofiber/fiber/v2 2.52.11`","depth":"midnight","depthScore":52,"depthScoreParts":{"impact":52.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}