logo

“Fiber” Optic Failure: Predictable UUIDs Expose Go Web Framework to Hijacking

ID: f27bc56f-a376-5f12-8e7b-34ad12319385

STIX ID: report--f27bc56f-a376-5f12-8e7b-34ad12319385

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-02-11

Date Updated: 2026-04-23

Author: Ddos

...
...

A critical vulnerability (CVE-2025-66630, CVSS 9.2) in Fiber v2 causes its UUID functions to silently return the all-zero UUID when crypto/rand fails on Go versions before 1.24, making session IDs, CSRF tokens, and other unique identifiers predictable and enabling session hijacking, CSRF bypass, and data corruption; maintainers fixed the issue in Fiber v2.52.11 and recommend upgrading Fiber or moving to Go 1.24+.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.