
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-66630 is a cryptographically weak pseudo-random number generator (PRNG) vulnerability in the Go web framework Fiber v2, where the internal utils.UUIDv4() and utils.UUID() functions silently fall back to generating a predictable all-zero UUID (00000000-0000-0000-0000-000000000000) when crypto/rand fails to obtain secure randomness. This affects all Fiber v2 versions prior to 2.52.11 running on Go 1.23 or earlier. The vulnerability was published on February 7, 2026, and assigned GHSA-68rr-p4fp-j59v. It carries a CVSS v3.1 base score of 9.4 (Critical) and a CVSS v4.0 base score of 9.2 (Critical) (Github Advisory, Fiber Security Advisory).
The root cause is classified as CWE-338 (Use of Cryptographically Weak Pseudo-Random Number Generator). On Go versions prior to 1.24, crypto/rand can return an error if the underlying entropy source (e.g., /dev/urandom) is unavailable — a condition more likely in containerized deployments, restricted sandboxes, chrooted environments, or embedded devices. When this error occurs, Fiber v2's UUIDv4() falls back to calling UUID(), which in turn silently returns the all-zero UUID rather than propagating the error. The fix (commit eb874b6) replaces the silent fallback with a panic, ensuring failures are visible rather than producing predictable identifiers. The vulnerability is particularly severe because Fiber v2 middleware components — including session management, CSRF protection, rate limiting, and request-ID generation — all default to calling utils.UUIDv4() for security-critical identifier generation (Github Advisory, Fiber Commit).
Successful exploitation enables attackers to predict or forge security-critical identifiers across multiple attack surfaces: session IDs become predictable, enabling session fixation or hijacking; CSRF tokens can be forged or bypassed; and authentication tokens become susceptible to replay attacks. When the all-zero UUID is generated, key-based data structures (session stores, rate-limit buckets, CSRF stores, caches) may collapse into a single shared key, causing state corruption, lock contention, or effective denial-of-service. Request-ID collisions additionally undermine logging and distributed tracing integrity, hampering incident response (Github Advisory, Fiber Security Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.012% (6th percentile), indicating low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires the target environment to be running Fiber v2 on Go 1.23 or earlier with a degraded or inaccessible entropy source — conditions more common in containerized or restricted environments than on standard Linux servers (Github Advisory).
X-Request-Id with zero or repeated UUIDs) or known deployment patterns in containerized/restricted environments./dev/urandom or equivalent entropy sources are unavailable or restricted, causing crypto/rand to return an error.00000000-0000-0000-0000-000000000000) or repeated UUIDs are observed, the fallback is active.X-Request-Id headers with the value 00000000-0000-0000-0000-000000000000 or repeated identical UUID values across multiple requests./dev/urandom or equivalent entropy sources (observable via container security audits or strace output showing failed reads from /dev/random//dev/urandom).The primary remediation is to upgrade Fiber v2 to version 2.52.11 or later, which replaces the silent fallback with a panic to make entropy failures visible (Fiber Release, Fiber Commit). As an interim mitigation for teams unable to upgrade Fiber immediately, upgrading the Go runtime to Go 1.24 or later eliminates the vulnerability, since Go 1.24 guarantees crypto/rand will block or panic rather than return an error. Additionally, audit applications for direct usage of utils.UUIDv4() or utils.UUID() in security-critical contexts and consider replacing them with alternative cryptographically secure UUID generation. Ensure containerized deployments have proper access to entropy sources (/dev/urandom) (Github Advisory).
The vulnerability was reported by @sixcolors, a Fiber maintainer and member of the security team, and published by ReneWerner87 on February 7, 2026. Coverage appeared across multiple security news outlets including SecurityOnline, CyberSecurityNews, CyberPress, and The Hacker News weekly recap, indicating moderate community attention. The vulnerability was also included in SUSE's govulncheck vulnerability database and tracked by Red Hat and Wolfi, suggesting broad ecosystem awareness. No significant controversy or disputed findings were noted in public commentary.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."