<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T15:50:53.150707+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-262941</id>
    <title>EUVD-2026-262941</title>
    <updated>2026-10-05T15:50:53.196894+00:00</updated>
    <content>EUVD-2026-262941</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-262941"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-66565</id>
    <title>fkie_cve-2025-66565</title>
    <updated>2026-10-05T15:50:53.196931+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Fiber Utils is a collection of common functions created for Fiber. In versions 2.0.0-rc.3 and below, when the system's cryptographic random number generator (crypto/rand) fails, both functions silently fall back to returning predictable UUID values, including the zero UUID "00000000-0000-0000-0000-000000000000". The vulnerability occurs through two related but distinct failure paths, both ultimately caused by crypto/rand.Read() failures, compromising the security of all Fiber applications using these functions for security-critical operations. This issue is fixed in version 2.0.0-rc.4.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-66565"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-m98w-cqp3-qcqr</id>
    <title>GHSA-m98w-cqp3-qcqr — Fiber Utils UUIDv4 and UUID Silent Fallback to Predictable Values</title>
    <updated>2026-10-05T15:50:53.196967+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/gofiber/utils/v2, Go: github.com/gofiber/utils</p>
<p>## Summary</p>
<p>Critical security vulnerabilities exist in both the `UUIDv4()` and `UUID()` functions of the `github.com/gofiber/utils` package. When the system's cryptographic random number generator (`crypto/rand`) fails, both functions silently fall back to returning predictable UUID values, the zero UUID `"00000000-0000-0000-0000-000000000000"`. This compromises the security of all Fiber applications using these functions for security-critical operations on **Go versions prior to 1.24**.</p>
<p>**Both functions are vulnerable to the same root cause (`crypto/rand` failure):**</p>
<p>* `UUIDv4()`: Indirect vulnerability through `uuid.NewRandom()` → `crypto/rand.Read()` → fallback to `UUID()`
* `UUID()`: Direct vulnerability through `crypto/rand.Read(uuidSeed[:])` → silent zero UUID return</p>
<p>&gt; **Note:** Go 1.24 and later panics on `crypto/rand` `Read()` failures, mitigating this vulnerability. Applications running on Go 1.24+ are not affected by the silent fallback behavior.</p>
<p>---</p>
<p>## Vulnerability Details</p>
<p>### Affected Functions</p>
<p>* **Package**: `github.com/gofiber/utils`
* **Functions**: `UUIDv4()` and `UUID()`
* **Return Type**: `string` (both functions)
* **Locations**: `common.go:93-99` (UUIDv4), `common.go:60-89` (UUID)</p>
<p>### Technical Description</p>
<p>The vulnerability occurs through two related but distinct failure paths, both ultimately caused by `crypto/rand.Read()` failures on Go &lt; 1.24:</p>
<p>#### Primary Path: UUIDv4() Vulnerability</p>
<p>1. `UUIDv4()` calls `google/uuid.NewRandom()` which inte…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-m98w-cqp3-qcqr"/>
  </entry>
</feed>
