go package report

Is github.com/gofiber/fiber/v2 safe?

10 known vulnerabilities, worst severity CRITICAL.

cvss
9.2

how bad it is if exploited, out of 10

epss
0.50%

chance of exploitation in the next 30 days

xyz score
not scored

CyberXYZ composite, out of 10

fig. 01 — GHSA-68rr-p4fp-j59v, the advisory selected below

// advisories

GHSA-68rr-p4fp-j59v

CRITICALCVE-2025-66630

Fiber v2 contains an internal vendored copy of gofiber/utils, and its functions UUIDv4() and UUID() inherit the same critical weakness described in the upstream advisory. On Go versions prior to 1.24, the underlying crypto/rand implementation can return an error if secure randomness cannot be obtained. In such cases, these Fiber v2 UUID functions silently fall back to generating predictable values

Affected
>=0, >=0, <2.52.11
Fixed in
2.52.11
Weakness
CWE-338
Published
2026-02-09
Source
github

GHSANVDMITRE


// ai model usage

Tracked for PyPI packages. HuggingFace models declare Python dependencies, so go packages are not covered.


Checked 2026-09-22 at 02:34 UTC. The most recent advisory here was published 2026-02-24. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is github.com/gofiber/fiber/v2 safe? go package security report | CyberXYZ