CVE-2025-66565

CRITICAL
Published Dec 9, 2025 Modified Dec 11, 2025 CWE-252 CWE-331 CWE-338

Description

Fiber Utils is a collection of common functions created for Fiber. In versions 2.0.0-rc.3 and below, when the system's cryptographic random number generator (crypto/rand) fails, both functions silently fall back to returning predictable UUID values, including the zero UUID "00000000-0000-0000-0000-000000000000". The vulnerability occurs through two related but distinct failure paths, both ultimately caused by crypto/rand.Read() failures, compromising the security of all Fiber applications using these functions for security-critical operations. This issue is fixed in version 2.0.0-rc.4.

CVSS v3.1 Score

9.8
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weakness Type (CWE)

CWE-252 CWE-252
CWE-331 CWE-331
CWE-338 CWE-338

Affected Products

Vendor Product
gofiber utils
gofiber utils
gofiber utils
gofiber utils
gofiber utils
gofiber utils
gofiber utils
gofiber utils
gofiber utils
gofiber utils
gofiber utils
gofiber utils
gofiber utils
gofiber utils
gofiber utils
gofiber utils
gofiber utils
gofiber utils
gofiber utils

References

Frequently Asked Questions

What is CVE-2025-66565? +
Fiber Utils is a collection of common functions created for Fiber. In versions 2.0.0-rc.3 and below, when the system's cryptographic random number generator (crypto/rand) fails, both functions silently fall back to returning predictable UUID values, including the zero UUID "00000000-0000-0000-0000-000000000000". The vulnerability occurs through two related but distinct failure paths, both ultimately caused by crypto/rand.Read() failures, compromising the security of all Fiber applications using these functions for security-critical operations. This issue is fixed in version 2.0.0-rc.4. It has a CVSS v3.1 base score of 9.8 (CRITICAL).
How severe is CVE-2025-66565? +
CVE-2025-66565 has a CVSS v3.1 score of 9.8 out of 10, rated CRITICAL. This is a critical vulnerability that should be patched immediately.
What products are affected by CVE-2025-66565? +
CVE-2025-66565 affects products from gofiber, specifically: utils. Check the affected products table above for specific version ranges.
How do I check if I'm vulnerable to CVE-2025-66565? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.

Related Vulnerabilities

Don't wait for an exploit

Scan your website for vulnerabilities like CVE-2025-66565 — free, no signup required.

Start Free Scan