Fiber Utils is a collection of common functions created for Fiber. In versions 2.0.0-rc.3 and below, when the system's cryptographic random number generator (crypto/rand) fails, both functions silently fall back to returning predictable UUID values, including the zero UUID "00000000-0000-0000-0000-000000000000". The vulnerability occurs through two related but distinct failure paths, both ultimately caused by crypto/rand.Read() failures, compromising the security of all Fiber applications using these functions for security-critical operations. This issue is fixed in version 2.0.0-rc.4.
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-m98w-cqp3-qcqr Fiber Utils UUIDv4 and UUID Silent Fallback to Predictable Values
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 11 Dec 2025 16:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:gofiber:utils:*:*:*:*:*:go:*:*
cpe:2.3:a:gofiber:utils:2.0.0:beta10:*:*:*:go:*:*
cpe:2.3:a:gofiber:utils:2.0.0:beta11:*:*:*:go:*:*
cpe:2.3:a:gofiber:utils:2.0.0:beta12:*:*:*:go:*:*
cpe:2.3:a:gofiber:utils:2.0.0:beta13:*:*:*:go:*:*
cpe:2.3:a:gofiber:utils:2.0.0:beta14:*:*:*:go:*:*
cpe:2.3:a:gofiber:utils:2.0.0:beta1:*:*:*:go:*:*
cpe:2.3:a:gofiber:utils:2.0.0:beta2:*:*:*:go:*:*
cpe:2.3:a:gofiber:utils:2.0.0:beta3:*:*:*:go:*:*
cpe:2.3:a:gofiber:utils:2.0.0:beta4:*:*:*:go:*:*
cpe:2.3:a:gofiber:utils:2.0.0:beta5:*:*:*:go:*:*
cpe:2.3:a:gofiber:utils:2.0.0:beta6:*:*:*:go:*:*
cpe:2.3:a:gofiber:utils:2.0.0:beta7:*:*:*:go:*:*
cpe:2.3:a:gofiber:utils:2.0.0:beta8:*:*:*:go:*:*
cpe:2.3:a:gofiber:utils:2.0.0:beta9:*:*:*:go:*:*
cpe:2.3:a:gofiber:utils:2.0.0:rc1:*:*:*:go:*:*
cpe:2.3:a:gofiber:utils:2.0.0:rc2:*:*:*:go:*:*
cpe:2.3:a:gofiber:utils:2.0.0:rc3:*:*:*:go:*:*
cpe:2.3:a:gofiber:utils:2.0.0:rc4:*:*:*:go:*:*
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Tue, 09 Dec 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 09 Dec 2025 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Gofiber
Gofiber utils
Vendors & Products Gofiber
Gofiber utils

Tue, 09 Dec 2025 02:00:00 +0000

Type Values Removed Values Added
Description Fiber Utils is a collection of common functions created for Fiber. In versions 2.0.0-rc.3 and below, when the system's cryptographic random number generator (crypto/rand) fails, both functions silently fall back to returning predictable UUID values, including the zero UUID "00000000-0000-0000-0000-000000000000". The vulnerability occurs through two related but distinct failure paths, both ultimately caused by crypto/rand.Read() failures, compromising the security of all Fiber applications using these functions for security-critical operations. This issue is fixed in version 2.0.0-rc.4.
Title Fiber Utils UUIDv4 and UUID Silent Fallback to Predictable Values
Weaknesses CWE-252
CWE-331
CWE-338
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-12-09T16:03:03.356Z

Reserved: 2025-12-04T16:05:22.975Z

Link: CVE-2025-66565

cve-icon Vulnrichment

Updated: 2025-12-09T14:17:01.343Z

cve-icon NVD

Status : Analyzed

Published: 2025-12-09T16:18:21.097

Modified: 2025-12-11T16:35:06.997

Link: CVE-2025-66565

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-12-09T10:26:31Z

Weaknesses