{"id":"CVE-2025-66565","aliases":["GHSA-m98w-cqp3-qcqr","GO-2025-4208"],"url":"https://o3.security/vulnerability/CVE-2025-66565","summary":"Fiber Utils UUIDv4 and UUID Silent Fallback to Predictable Values","details":"Fiber Utils is a collection of common functions created for Fiber. In versions 2.0.0-rc.3 and below, when the system's cryptographic random number generator (crypto/rand) fails, both functions silently fall back to returning predictable UUID values, including the zero UUID \"00000000-0000-0000-0000-000000000000\". The vulnerability occurs through two related but distinct failure paths, both ultimately caused by crypto/rand.Read() failures, compromising the security of all Fiber applications using these functions for security-critical operations. This issue is fixed in version 2.0.0-rc.4.","published":"2025-12-09T01:47:58.430Z","modified":"2026-08-12T03:51:48.098878920Z","cvss":null,"epss":{"score":0.00458,"percentile":0.37725,"asOf":"2026-08-24"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/gofiber/utils/v2","fixedVersion":"2.0.0-rc.4"},{"ecosystem":"Go","name":"github.com/gofiber/utils","fixedVersion":"1.2.0"}],"fix":{"url":"https://github.com/gofiber/utils/commit/6c6cf047032b9c8dff43d29f990b4b10e9b02d47","label":"gofiber/utils@6c6cf04"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/66xxx/CVE-2025-66565.json"},{"type":"ADVISORY","url":"https://github.com/gofiber/utils/security/advisories/GHSA-m98w-cqp3-qcqr"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-66565"},{"type":"FIX","url":"https://github.com/gofiber/utils/commit/6c6cf047032b9c8dff43d29f990b4b10e9b02d47"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:48.098878920Z"}}