“Fiber” Optic Failure: Predictable UUIDs Expose Go Web Framework to Hijacking
ID: f27bc56f-a376-5f12-8e7b-34ad12319385
STIX ID: report--f27bc56f-a376-5f12-8e7b-34ad12319385
Feed Name: securityonline.info
Threat Score
A critical vulnerability (CVE-2025-66630, CVSS 9.2) in Fiber v2 causes its UUID functions to silently return the all-zero UUID when crypto/rand fails on Go versions before 1.24, making session IDs, CSRF tokens, and other unique identifiers predictable and enabling session hijacking, CSRF bypass, and data corruption; maintainers fixed the issue in Fiber v2.52.11 and recommend upgrading Fiber or moving to Go 1.24+.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
