logo

Critical UUID Flaw in Fiber v2 on Go 1.24+ Enables Session Hijacking, CSRF Bypass, and Zero-ID DoS Risk

ID: b0fc2596-84de-54fd-85d5-a5e64550e909

STIX ID: report--b0fc2596-84de-54fd-85d5-a5e64550e909

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-02-11

Date Updated: 2026-04-21

Author: Abinaya

...
...

A critical vulnerability (CVE-2025-66630) in Fiber v2 on Go (affecting versions < 2.52.11 running on Go 1.23 or earlier) causes UUID generation to silently fall back to the predictable zero UUID when the RNG fails, enabling session hijacking, CSRF bypass, authentication token guessing, and potential denial-of-service due to shared session keys; a patch (Fiber 2.52.11) is available and administrators are advised to upgrade and verify secure randomness sources.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.