GHSA-68rr-p4fp-j59v
CRITICALCVE-2025-66630Fiber v2 contains an internal vendored copy of gofiber/utils, and its functions UUIDv4() and UUID() inherit the same critical weakness described in the upstream advisory. On Go versions prior to 1.24, the underlying crypto/rand implementation can return an error if secure randomness cannot be obtained. In such cases, these Fiber v2 UUID functions silently fall back to generating predictable values
- Affected
- >=0, >=0, <2.52.11
- Fixed in
- 2.52.11
- Weakness
- CWE-338
- Published
- 2026-02-09
- Source
- github