Cryptographic Weakness in Fiber Utils Vulnerability Affecting Fiber
CVE-2025-66565
What is CVE-2025-66565?
The Fiber Utils library contains functions that inadvertently fall back to generating predictable UUIDs when the cryptographic random number generator fails. This behavior compromises the integrity of any application relying on these functions for cryptographic security, as it may expose sensitive operations to potential exploits. The issue arises from failures in crypto/rand.Read(), revealing predictable UUIDs, including the zero UUID, which can undermine the overall security posture of applications built with Fiber. This vulnerability is resolved in version 2.0.0-rc.4.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
utils github.com/gofiber/utils <= 1.2.0 <= github.com/gofiber/utils 1.2.0
utils github.com/gofiber/utils/v2 < 2.0.0-rc.4 < github.com/gofiber/utils/v2 2.0.0-rc.4
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
