Improper Certificate Validation in go-micro by Micro, Inc.
CVE-2026-105216
9.1CRITICAL
What is CVE-2026-105216?
The go-micro library, prior to version 6.0.0, has a vulnerability related to improper TLS certificate validation. This issue arises because the shared TLS helper is configured with InsecureSkipVerify set to true by default. As a result, an attacker can perform man-in-the-middle attacks, allowing them to impersonate services and intercept communication. This vulnerability affects gRPC transport, HTTP and RabbitMQ broker traffic, as well as data exchanges with Consul and etcd registries, potentially exposing sensitive information such as authentication tokens and credentials. Users are advised to update to the latest version to mitigate the risks associated with this vulnerability.
Affected Version(s)
go-micro 0 < 6.0.0
