Critical security vulnerabilities exist in both the UUIDv4() and UUID() functions of the github.com/gofiber/utils package. When the system's cryptographic random number generator (crypto/rand) fails, both functions silently fall back to returning predictable UUID values, the zero UUID "00000000-0000-0000-0000-000000000000". This compromises the security of all Fiber applications using these functions for security-critical operations on Go versions prior to 1.24.
Both functions are vulnerable to the same root cause (crypto/rand failure):
UUIDv4(): Indirect vulnerability through uuid.NewRandom() → crypto/rand.Read() → fallback to UUID()UUID(): Direct vulnerability through crypto/rand.Read(uuidSeed[:]) → silent zero UUID returnNote: Go 1.24 and later panics on
crypto/randRead()failures, mitigating this vulnerability. Applications running on Go 1.24+ are not affected by the silent fallback behavior.
github.com/gofiber/utilsUUIDv4() and UUID()string (both functions)common.go:93-99 (UUIDv4), common.go:60-89 (UUID)The vulnerability occurs through two related but distinct failure paths, both ultimately caused by crypto/rand.Read() failures on Go < 1.24:
UUIDv4() calls google/uuid.NewRandom() which internally uses crypto/rand.Read()uuid.NewRandom() fails, UUIDv4() falls back to the internal UUID() functionUUID() directly calls crypto/rand.Read(uuidSeed[:]) to seed its internal stateUUID() silently fails and returns the zero UUID "00000000-0000-0000-0000-000000000000"func UUIDv4() string {
token, err := uuid.NewRandom() // Uses crypto/rand.Read() internally
if err != nil {
return UUID() // Dangerous fallback - no error returned to application
}
return token.String()
}
func UUID() string {
uuidSetup.Do(func() {
if _, err := rand.Read(uuidSeed[:]); err != nil { // Direct crypto/rand.Read() call
return // Silent failure - no seeding, uuidCounter remains 0
}
uuidCounter = binary.LittleEndian.Uint64(uuidSeed[:8])
})
if atomic.LoadUint64(&uuidCounter) <= 0 {
return "00000000-0000-0000-0000-000000000000" // Zero UUID returned silently
}
// ... generate UUID from counter
}
Root Cause: Both vulnerabilities stem from crypto/rand.Read() failures, occurring through different code paths with the same dangerous silent fallback behavior.
This issue is especially severe because many Fiber middleware packages (session, CSRF, auth, rate-limit, request-ID, etc.) default to utils.UUIDv4() for generating security-sensitive identifiers. A failure in crypto/rand would cause every generated identifier across the entire application to collapse to a single predictable value (the zero UUID), resulting in:
While entropy exhaustion is extremely rare on modern Linux systems, RNG access failures (e.g., restricted /dev/random or /dev/urandom access, broken container environments, sandbox restrictions, misconfigured VMs, or FIPS-mode RNG failures) are realistic. In these scenarios on Go < 1.24, crypto/rand may return errors immediately — triggering the vulnerable fallback paths.
On Go 1.24+, crypto/rand Read() panics on failure, mitigating the silent-zero fallback issue.
uuid.NewRandom() fails (indirect crypto/rand.Read() failure)UUIDv4() calls UUID() as fallback with no error returnedUUID() seeding fails directly via crypto/rand.Read(uuidSeed[:])"00000000-0000-0000-0000-000000000000" is returned silentlygithub.com/gofiber/utils containing the UUIDv4() or UUID() functionsUUIDv4() or UUID for securitycrypto/rand Read() failures and is not affectedReplace usage of utils.UUIDv4() with uuid.New() or wait for fix:
sessionID := uuid.New()
Modify utils.UUIDv4() and utils.UUID() to fail explicitly when cryptographic randomness is unavailable:
func UUIDv4() string {
token, err := uuid.NewRandom()
if err != nil {
panic(fmt.Sprintf("utils: failed to generate secure UUID: %v", err))
}
return token.String()
}
func UUID() string {
uuidSetup.Do(func() {
if _, err := rand.Read(uuidSeed[:]); err != nil {
panic(fmt.Sprintf("utils: failed to seed UUID generator: %v", err))
}
uuidCounter = binary.LittleEndian.Uint64(uuidSeed[:8])
})
if atomic.LoadUint64(&uuidCounter) <= 0 {
panic("utils: UUID generator not properly seeded")
}
// ... generate UUID from counter
}
Applications can detect if they're affected by:
github.com/gofiber/utilsUUIDv4() and UUID() usage in security-critical code pathsUUIDv4() for security identifierscrypto/rand behavior changes: golang/go#66821, Go 1.25.5 sourceReported by: @sixcolors
{
"cwe_ids": [
"CWE-252",
"CWE-331",
"CWE-338"
],
"github_reviewed": true,
"github_reviewed_at": "2025-12-08T17:57:26Z",
"nvd_published_at": "2025-12-09T16:18:21Z",
"severity": "CRITICAL"
}