CVE-2026-105216: go-micro before 6.0.0 Disabled TLS Certificate Verification via tls.Config Helper

Published Oct 4, 2026
·
Updated

go-micro before 6.0.0 contains an improper certificate validation vulnerability that allows network attackers to impersonate services because the shared TLS helper sets InsecureSkipVerify to true by default. Man-in-the-middle attackers can present any certificate to intercept or modify gRPC transport, HTTP and RabbitMQ broker, and Consul or etcd registry traffic, including authentication tokens and credentials.

Affected Software

1 affected component
go/micro/go-micro<6.0.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade go-micro to a version that resolves this vulnerability.

    Fixed in 6.0.0

Event History

Oct 4, 2026
CVE Published
via MITRE·05:09 PM
Data Sourced
via MITRE·05:09 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:16 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed?

Deployments using go-micro before 6.0.0 that rely on the shared TLS helper are exposed. The affected traffic includes gRPC transport, HTTP, RabbitMQ broker connections, and Consul or etcd registry traffic.

2

Is a default configuration affected?

Yes. The shared TLS helper sets InsecureSkipVerify to true by default, disabling TLS certificate verification unless the application overrides that behavior.

3

What does an attacker need to exploit this?

An attacker needs a network position that allows man-in-the-middle interception of the affected TLS traffic. No authentication or user interaction is required, but exploitation is rated high complexity.

4

What is the likely impact of successful exploitation?

A network attacker can impersonate services and intercept or modify affected traffic. This can expose or alter authentication tokens, credentials, and other data carried over those connections.

5

How can teams determine whether they are affected?

Check whether the application uses go-micro before version 6.0.0 and whether its TLS configuration is created through the shared TLS helper. Also review TLS settings for InsecureSkipVerify being enabled on service, broker, or registry connections.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203