PT-2025-49761 · Unknown · Fiber Utils

Published

2025-12-09

·

Updated

2026-01-06

·

CVE-2025-66565

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Fiber Utils versions 2.0.0-rc.3 and below
Description Fiber Utils is a collection of functions for Fiber. In versions 2.0.0-rc.3 and below, if the system’s cryptographic random number generator (crypto/rand) fails, the software silently reverts to generating predictable UUID values, including the zero UUID "00000000-0000-0000-0000-000000000000". This occurs due to failures in the crypto/rand.Read() function, potentially compromising the security of Fiber applications using these functions for security-critical operations.
Recommendations Update to version 2.0.0-rc.4 or later.

Exploit

Fix

Unchecked Return Value

Weakness Enumeration

Related Identifiers

CVE-2025-66565
GHSA-M98W-CQP3-QCQR
GO-2025-4208
SUSE-SU-2026:0037-1

Affected Products

Fiber Utils