Improper Certificate Validation in go-micro by Micro, Inc.
CVE-2026-105216

9.1CRITICAL

Key Information:

Vendor

Micro

Status
Vendor
CVE Published:
4 October 2026

What is CVE-2026-105216?

The go-micro library, prior to version 6.0.0, has a vulnerability related to improper TLS certificate validation. This issue arises because the shared TLS helper is configured with InsecureSkipVerify set to true by default. As a result, an attacker can perform man-in-the-middle attacks, allowing them to impersonate services and intercept communication. This vulnerability affects gRPC transport, HTTP and RabbitMQ broker traffic, as well as data exchanges with Consul and etcd registries, potentially exposing sensitive information such as authentication tokens and credentials. Users are advised to update to the latest version to mitigate the risks associated with this vulnerability.

Affected Version(s)

go-micro 0 < 6.0.0

References

CVSS V4

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Siyang Wu
.