Fiber v2 disclosed a high-severity weakness in its UUID generation helpers (utils.UUIDv4() / utils.UUID()) tracked as CVE-2025-66630 (CVSS v4.0 9.2, CWE-338). On Go versions prior to 1.24, crypto/rand can return an error when secure randomness is unavailable; Fiber’s UUID functions did not propagate that error, allowing applications and middleware to unknowingly proceed with predictable, repeated, or low-entropy identifiers. Reporting indicates Fiber could silently fall back to a “zero UUID” (00000000-0000-0000-0000-000000000000) in this failure mode, creating security-critical token predictability without developer visibility.
The impact spans common middleware defaults that rely on these UUIDs, including session identifiers, CSRF tokens, request IDs, and other security-sensitive values, enabling scenarios such as session hijacking, CSRF protection bypass, and potential service disruption/DoS conditions when identifiers collapse to a constant value. The issue affects Fiber v2 versions before 2.52.11 when running on Go <1.24; Fiber 2.52.11 remediates the problem, and newer Go versions change the underlying behavior around randomness failures (e.g., blocking/panicking rather than returning an error), reducing exposure compared to older runtimes.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
Public reporting described how the flaw could lead to session hijacking, CSRF bypass, unauthorized access, and denial-of-service in environments where secure randomness is unavailable or misconfigured. The disclosure also clarified that Go 1.24+ handles randomness failures differently, reducing exposure on newer Go versions.
The issue was remediated in Fiber version 2.52.11, which addressed the insecure handling of crypto/rand failures in UUID generation. The fix removed the vulnerable behavior affecting earlier Fiber v2 releases in impacted environments.
A vulnerability existed in Fiber v2 in which utils.UUIDv4() / utils.UUID() could silently produce predictable or all-zero UUIDs when crypto/rand failed on Go 1.23 or earlier. This exposed applications using those UUIDs for sessions, CSRF tokens, and other security-sensitive identifiers to risks such as session hijacking, token guessing, and collisions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.