CVE-2025-66565: Gofiber Utils

Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.

Fiber Utils is a collection of common functions created for Fiber. In versions 2.0.0-rc.3 and below, when the system's cryptographic random number generator (crypto/rand) fails, both functions silently fall back to returning predictable UUID values, including the zero UUID "00000000-0000-0000-0000-000000000000". The vulnerability occurs through two related but distinct failure paths, both ultimately caused by crypto/rand.Read() failures, compromising the security of all Fiber applications using these functions for security-critical operations. This issue is fixed in version 2.0.0-rc.4.

Affected products

  • Gofiber Utils: up to and including 1.2.0; version 2.0.0 only

Published 2025-12-09. Last modified 2026-10-07.