2026-10-04 17:9CVE-2026-105216VulnCheck
PUBLISHED5.2CWE-295

go-micro before 6.0.0 Disabled TLS Certificate Verification via tls.Config Helper

go-micro before 6.0.0 contains an improper certificate validation vulnerability that allows network attackers to impersonate services because the shared TLS helper sets InsecureSkipVerify to true by default. Man-in-the-middle attackers can present any certificate to intercept or modify gRPC transport, HTTP and RabbitMQ broker, and Consul or etcd registry traffic, including authentication tokens and credentials.

Problem type

Affected products

micro

go-micro

< 6.0.0 - AFFECTED

References

JSON source

https://cveawg.mitre.org/api/cve/CVE-2026-105216
Click to expand
{
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "cveMetadata": {
    "cveId": "CVE-2026-105216",
    "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
    "assignerShortName": "VulnCheck",
    "dateUpdated": "2026-10-04T17:09:52.327Z",
    "dateReserved": "2026-10-04T13:04:00.478Z",
    "datePublished": "2026-10-04T17:09:52.327Z",
    "state": "PUBLISHED"
  },
  "containers": {
    "cna": {
      "providerMetadata": {
        "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "shortName": "VulnCheck",
        "dateUpdated": "2026-10-04T17:09:52.327Z"
      },
      "datePublic": "2026-06-15T00:00:00.000Z",
      "title": "go-micro before 6.0.0 Disabled TLS Certificate Verification via tls.Config Helper",
      "descriptions": [
        {
          "lang": "en",
          "value": "go-micro before 6.0.0 contains an improper certificate validation vulnerability that allows network attackers to impersonate services because the shared TLS helper sets InsecureSkipVerify to true by default. Man-in-the-middle attackers can present any certificate to intercept or modify gRPC transport, HTTP and RabbitMQ broker, and Consul or etcd registry traffic, including authentication tokens and credentials."
        }
      ],
      "affected": [
        {
          "vendor": "micro",
          "product": "go-micro",
          "defaultStatus": "unaffected",
          "versions": [
            {
              "version": "0",
              "status": "affected",
              "versionType": "semver",
              "lessThan": "6.0.0"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "lang": "en",
              "description": "Improper Certificate Validation",
              "cweId": "CWE-295",
              "type": "CWE"
            }
          ]
        }
      ],
      "references": [
        {
          "url": "https://github.com/micro/go-micro/issues/2963",
          "name": "GitHub Issue #2963",
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/micro/go-micro/commit/c7657f73f45cf839e643db10f28703eeab7299c3",
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/micro/go-micro/blob/v5.30.0/internal/util/tls/tls.go#L43-L67",
          "tags": [
            "technical-description"
          ]
        },
        {
          "url": "https://github.com/micro/go-micro",
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/go-micro-before-6.0.0-disabled-tls-certificate-verification-via-tls-config-helper",
          "name": "VulnCheck Advisory: go-micro before 6.0.0 Disabled TLS Certificate Verification via tls.Config Helper",
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "metrics": [
        {
          "format": "CVSS"
        },
        {
          "format": "CVSS",
          "cvssV3_1": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "scope": "UNCHANGED",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "availabilityImpact": "NONE",
            "baseScore": 7.4,
            "baseSeverity": "HIGH"
          }
        }
      ],
      "credits": [
        {
          "lang": "en",
          "value": "Siyang Wu",
          "type": "finder"
        }
      ]
    }
  }
}