CVE-2025-66630Disclosure(gofiber / fiber)

LOWCVSS 9.4 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch gofiber fiber systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Fiber is an Express inspired web framework written in Go. Before 2.52.11, on Go versions prior to 1.24, the underlying crypto/rand implementation can return an error if secure randomness cannot be obtained. Because no error is returned by the Fiber v2 UUID functions, application code may unknowingly rely on predictable, repeated, or low-entropy identifiers in security-critical pathways. This is especially impactful because many Fiber v2 middleware components (session middleware, CSRF, rate limiting, request-ID generation, etc.) default to using utils.UUIDv4(). This vulnerability is fixed in 2.52.11.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-338

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fiber
  • go

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 1d ago at 3 mentions (2026-02-11); latest day: 1
  • 6 total mentions across 3 days

Affected systems

Products
fibergo

Deep dive

Activity timeline6 mentions / 3d
01223Mentions · 2026-02-09: 2Mentions · 2026-02-11: 3Mentions · 2026-02-19: 1Patch / Workaround · 2026-02-11: 1Patch / Workaround · 2026-02-19: 1Technical Details · 2026-02-09: 2Technical Details · 2026-02-11: 1Technical Details · 2026-02-19: 102-0902-1102-19
Signal classification3 categories
Disclosure
233.3%
General
233.3%
Patch
233.3%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-092
Disclosure2
2026-02-113
General2Patch1
2026-02-191
Patch1
Full discourse6 posts
  • iototsecnews@iototsecnews
    Patch

    Fiber v2 の脆弱性 CVE-2025-66630 が FIX:UUID の不備によるセッション・ハイジャックなどの可能性 https://iototsecnews.jp/2026/02/11/critical-uuid-flaw-in-fiber-v2-on-go-1-24-enables-session-hijacking-csrf-bypass-and-zero-id-dos-risk/ この問題の原因は、Go 言語の Web フレームワークである Fiber v2 が識別子 UUID を生成する際に、安全な乱数が取得できない状況に陥ると、エラーを出さずに “ゼロ UUID” を秘密裏に発行してしまうという仕組みにあります。UUID は、セッション ID や CSRF 対策トークンなどの、きわめて重要な鍵として使われるものです。本来であれば、乱数生成に失敗した場合には処理を止めるべきですが、固定値である “00000000-0000-0000-0000-000000000000” を代わりに使って動作を継続してしまう問題があります。その結果として、この “ゼロ” の値を予測する攻撃者が、他人のセッションを乗っ取るといった侵害が成立してしまいます。ご利用のチームは、ご注意ください。 #CVE202566630 #Fiberv2 #Vulnerability

    Post summary

    CVE‑2025‑66630 in Fiber v2 allows attackers to hijack sessions by exploiting a zero UUID bug; the article details the flaw and notes that a fix is available, with no evidence of active exploitation.

    01000132
    484 followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    The `Fiber` web framework (CVE-2025-66630) may generate predictable UUIDs if `crypto/rand` fails. This could impact application security if UUIDs are used for sensitive identifiers. Update to `2.52.11`. #Go #WebFramework #Security https://www.pulsepatch.io/posts/cve-2025-66630-gofiber-fiber-predictable-uuid

    Post summary

    CVE-2025-66630 in the Fiber framework causes predictable UUIDs when crypto/rand fails; updating to version 2.52.11 resolves the issue.

    0000039
    1 followersView on X
  • VulnTracker@vuln_tracker
    General

    @the_yellow_fall You now can see the full detail from https://vulntracker.io/cves/CVE-2025-66630

    Post summary

    The tweet only shares a link to a vulnerability tracker page for CVE‑2025‑66630, with no further information about the vulnerability or its exploitation.

    0000042
    333 followersView on X
  • VulnTracker@vuln_tracker
    General

    @the_yellow_fall You now can see the full detail about CVE-2025-66630 from https://vulntracker.io/cves/CVE-2025-66630

    Post summary

    The tweet simply directs readers to a URL for detailed information on CVE‑2025‑66630, with no additional context or evidence provided.

    0000035
    333 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-66630 Fiber is an Express inspired web framework written in Go. Before 2.52.11, on Go versions prior to 1.24, the underlying crypto/rand implementation can return an error … https://www.cve.org/CVERecord?id=CVE-2025-66630

    Post summary

    The text discloses that CVE‑2025‑66630 involves a crypto/rand error in Fiber for Go versions <1.24, without providing PoC, exploit, patch, or evidence of active exploitation.

    00000201
    56.5K followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2025-66630: The Null Identity: Unmasking Fiber's Critical 'Zero-UUID' Vulnerability A critical failure in the Fiber web framework's random number generation logic allows for the creation of predictable, zero-value UUIDs. This flaw leads to catastr... https://cvereports.com/reports/CVE-2025-66630

    Post summary

    The post discloses a critical flaw in Fiber's UUID generation that can produce predictable zero-value UUIDs, but provides no PoC, exploit code, or mitigation details.

    0000038
    27 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appgofiberfiber-go-
Appgolanggo---

Explore more