CVE-2026-105216: go-micro before 6.0.0 Disabled TLS Certificate Verification via tls.Config Helper
go-micro before 6.0.0 contains an improper certificate validation vulnerability that allows network attackers to impersonate services because the shared TLS helper sets InsecureSkipVerify to true by default. Man-in-the-middle attackers can present any certificate to intercept or modify gRPC transport, HTTP and RabbitMQ broker, and Consul or etcd registry traffic, including authentication tokens and credentials.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
go-microto a version that resolves this vulnerability.Fixed in 6.0.0
Event History
Frequently Asked Questions
Which deployments are exposed?
Deployments using go-micro before 6.0.0 that rely on the shared TLS helper are exposed. The affected traffic includes gRPC transport, HTTP, RabbitMQ broker connections, and Consul or etcd registry traffic.
Is a default configuration affected?
Yes. The shared TLS helper sets InsecureSkipVerify to true by default, disabling TLS certificate verification unless the application overrides that behavior.
What does an attacker need to exploit this?
An attacker needs a network position that allows man-in-the-middle interception of the affected TLS traffic. No authentication or user interaction is required, but exploitation is rated high complexity.
What is the likely impact of successful exploitation?
A network attacker can impersonate services and intercept or modify affected traffic. This can expose or alter authentication tokens, credentials, and other data carried over those connections.
How can teams determine whether they are affected?
Check whether the application uses go-micro before version 6.0.0 and whether its TLS configuration is created through the shared TLS helper. Also review TLS settings for InsecureSkipVerify being enabled on service, broker, or registry connections.