CVE-2025-66630: 
Alma Linux vulnerability analysis and mitigation

Overview

CVE-2025-66630 is a cryptographically weak pseudo-random number generator (PRNG) vulnerability in the Go web framework Fiber v2, where the internal utils.UUIDv4() and utils.UUID() functions silently fall back to generating a predictable all-zero UUID (00000000-0000-0000-0000-000000000000) when crypto/rand fails to obtain secure randomness. This affects all Fiber v2 versions prior to 2.52.11 running on Go 1.23 or earlier. The vulnerability was published on February 7, 2026, and assigned GHSA-68rr-p4fp-j59v. It carries a CVSS v3.1 base score of 9.4 (Critical) and a CVSS v4.0 base score of 9.2 (Critical) (Github Advisory, Fiber Security Advisory).

Technical details

The root cause is classified as CWE-338 (Use of Cryptographically Weak Pseudo-Random Number Generator). On Go versions prior to 1.24, crypto/rand can return an error if the underlying entropy source (e.g., /dev/urandom) is unavailable — a condition more likely in containerized deployments, restricted sandboxes, chrooted environments, or embedded devices. When this error occurs, Fiber v2's UUIDv4() falls back to calling UUID(), which in turn silently returns the all-zero UUID rather than propagating the error. The fix (commit eb874b6) replaces the silent fallback with a panic, ensuring failures are visible rather than producing predictable identifiers. The vulnerability is particularly severe because Fiber v2 middleware components — including session management, CSRF protection, rate limiting, and request-ID generation — all default to calling utils.UUIDv4() for security-critical identifier generation (Github Advisory, Fiber Commit).

Impact

Successful exploitation enables attackers to predict or forge security-critical identifiers across multiple attack surfaces: session IDs become predictable, enabling session fixation or hijacking; CSRF tokens can be forged or bypassed; and authentication tokens become susceptible to replay attacks. When the all-zero UUID is generated, key-based data structures (session stores, rate-limit buckets, CSRF stores, caches) may collapse into a single shared key, causing state corruption, lock contention, or effective denial-of-service. Request-ID collisions additionally undermine logging and distributed tracing integrity, hampering incident response (Github Advisory, Fiber Security Advisory).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.012% (6th percentile), indicating low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires the target environment to be running Fiber v2 on Go 1.23 or earlier with a degraded or inaccessible entropy source — conditions more common in containerized or restricted environments than on standard Linux servers (Github Advisory).

Exploitation steps

  1. Reconnaissance: Identify applications built with Fiber v2 (versions < 2.52.11) running on Go 1.23 or earlier. Indicators may include HTTP response headers (e.g., X-Request-Id with zero or repeated UUIDs) or known deployment patterns in containerized/restricted environments.
  2. Trigger entropy failure: In environments where the attacker can influence the deployment context (e.g., a shared container platform), create conditions where /dev/urandom or equivalent entropy sources are unavailable or restricted, causing crypto/rand to return an error.
  3. Observe predictable UUID generation: Monitor session cookies, CSRF tokens, or request IDs returned by the application. If the zero UUID (00000000-0000-0000-0000-000000000000) or repeated UUIDs are observed, the fallback is active.
  4. Session hijacking: Use the known/predicted session ID (e.g., the zero UUID) to craft a session cookie and send requests to the application, gaining access to another user's session.
  5. CSRF bypass: Forge a CSRF token using the known zero UUID value and submit state-changing requests that bypass CSRF protection.
  6. Authentication replay: Predict or reuse authentication tokens generated with the zero UUID to replay authenticated requests or impersonate other users (Github Advisory, Fiber Security Advisory).

Indicators of compromise

  • Network: HTTP responses containing session cookies, CSRF tokens, or X-Request-Id headers with the value 00000000-0000-0000-0000-000000000000 or repeated identical UUID values across multiple requests.
  • Logs: Application access logs showing multiple distinct clients sharing the same session ID or request ID; CSRF validation failures followed by successful state-changing requests using the zero UUID token.
  • Application Behavior: Rate-limiting middleware failing to distinguish between different clients (all sharing the same rate-limit key); session store entries collapsing to a single key; CSRF store containing only one entry shared across all users.
  • Process/Environment: Go application running with restricted access to /dev/urandom or equivalent entropy sources (observable via container security audits or strace output showing failed reads from /dev/random//dev/urandom).

Mitigation and workarounds

The primary remediation is to upgrade Fiber v2 to version 2.52.11 or later, which replaces the silent fallback with a panic to make entropy failures visible (Fiber Release, Fiber Commit). As an interim mitigation for teams unable to upgrade Fiber immediately, upgrading the Go runtime to Go 1.24 or later eliminates the vulnerability, since Go 1.24 guarantees crypto/rand will block or panic rather than return an error. Additionally, audit applications for direct usage of utils.UUIDv4() or utils.UUID() in security-critical contexts and consider replacing them with alternative cryptographically secure UUID generation. Ensure containerized deployments have proper access to entropy sources (/dev/urandom) (Github Advisory).

Community reactions

The vulnerability was reported by @sixcolors, a Fiber maintainer and member of the security team, and published by ReneWerner87 on February 7, 2026. Coverage appeared across multiple security news outlets including SecurityOnline, CyberSecurityNews, CyberPress, and The Hacker News weekly recap, indicating moderate community attention. The vulnerability was also included in SUSE's govulncheck vulnerability database and tracked by Red Hat and Wolfi, suggesting broad ecosystem awareness. No significant controversy or disputed findings were noted in public commentary.

Additional resources


Source: This report was generated using AI

Related Alma Linux vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-93546HIGH8.8
  • Apache HTTP Server logoApache HTTP Server
  • cpe:2.3:a:apache:http_server
NoYesOct 01, 2026
CVE-2026-73636HIGH8.1
  • Apache HTTP Server logoApache HTTP Server
  • httpd:2.4::mod_proxy_html
NoYesOct 01, 2026
CVE-2026-63718HIGH7.5
  • Apache HTTP Server logoApache HTTP Server
  • httpd:2.4::httpd-manual
NoYesOct 01, 2026
CVE-2026-73637HIGH7.3
  • Apache HTTP Server logoApache HTTP Server
  • httpd
NoYesOct 01, 2026
CVE-2026-79768MEDIUM5.3
  • Apache HTTP Server logoApache HTTP Server
  • httpd:2.4::mod_session
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management