9.8

CVE-2025-66565

Fiber Utils UUIDv4 and UUID Silent Fallback to Predictable Values

Fiber Utils is a collection of common functions created for Fiber. In versions 2.0.0-rc.3 and below, when the system's cryptographic random number generator (crypto/rand) fails, both functions silently fall back to returning predictable UUID values, including the zero UUID "00000000-0000-0000-0000-000000000000". The vulnerability occurs through two related but distinct failure paths, both ultimately caused by crypto/rand.Read() failures, compromising the security of all Fiber applications using these functions for security-critical operations. This issue is fixed in version 2.0.0-rc.4.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Gofiber ≫ Utils SwPlatform go Version <= 1.2.0
Gofiber ≫ Utils Version 2.0.0 Update beta1 SwPlatform go
Gofiber ≫ Utils Version 2.0.0 Update beta10 SwPlatform go
Gofiber ≫ Utils Version 2.0.0 Update beta11 SwPlatform go
Gofiber ≫ Utils Version 2.0.0 Update beta12 SwPlatform go
Gofiber ≫ Utils Version 2.0.0 Update beta13 SwPlatform go
Gofiber ≫ Utils Version 2.0.0 Update beta14 SwPlatform go
Gofiber ≫ Utils Version 2.0.0 Update beta2 SwPlatform go
Gofiber ≫ Utils Version 2.0.0 Update beta3 SwPlatform go
Gofiber ≫ Utils Version 2.0.0 Update beta4 SwPlatform go
Gofiber ≫ Utils Version 2.0.0 Update beta5 SwPlatform go
Gofiber ≫ Utils Version 2.0.0 Update beta6 SwPlatform go
Gofiber ≫ Utils Version 2.0.0 Update beta7 SwPlatform go
Gofiber ≫ Utils Version 2.0.0 Update beta8 SwPlatform go
Gofiber ≫ Utils Version 2.0.0 Update beta9 SwPlatform go
Gofiber ≫ Utils Version 2.0.0 Update rc1 SwPlatform go
Gofiber ≫ Utils Version 2.0.0 Update rc2 SwPlatform go
Gofiber ≫ Utils Version 2.0.0 Update rc3 SwPlatform go
Gofiber ≫ Utils Version 2.0.0 Update rc4 SwPlatform go
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.46% 0.374
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
security-advisories@github.com 9.3 0 0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-252 Unchecked Return Value

The product does not check the return value from a method or function, which can prevent it from detecting unexpected states and conditions.

CWE-331 Insufficient Entropy

The product uses an algorithm or scheme that produces insufficient entropy, leaving patterns or clusters of values that are more likely to occur than others.

CWE-338 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)

The product uses a Pseudo-Random Number Generator (PRNG) in a security context, but the PRNG's algorithm is not cryptographically strong.

https://github.com/gofiber/utils/commit/6c6cf047032b9c8dff43d29f990b4b10e9b02d47
Patch
https://github.com/gofiber/utils/security/advisories/GHSA-m98w-cqp3-qcqr
Vendor Advisory