Skip to content
Threat Feed
high advisory

Improper Certificate Validation in go-micro

The go-micro library versions prior to 6.0.0 insecurely configure TLS validation by default, enabling man-in-the-middle attacks to intercept traffic and harvest credentials.

CVE search metadata

CVE search record: CVE-2026-105216. Severity: high. CVSS: 7.4. KEV: no. Product: go-micro (< 6.0.0). Brief: Improper Certificate Validation in go-micro. Brief link: https://feed.craftedsignal.io/briefs/2026-10-go-micro-tls/

The go-micro framework versions before 6.0.0 contain a critical vulnerability where the shared TLS helper defaults the InsecureSkipVerify configuration to true. This default setting bypasses standard X.509 certificate validation, allowing network-adjacent attackers to perform man-in-the-middle (MitM) attacks. By positioning themselves between microservices or between a service and its broker/registry, an attacker can silently intercept, inspect, or modify traffic. The impact is significant, as the vulnerability affects critical communication channels including gRPC, HTTP, RabbitMQ broker traffic, and service registry interactions with Consul or etcd. Successful exploitation provides attackers with the capability to steal authentication tokens and administrative credentials, facilitating further lateral movement or data exfiltration within the microservices environment.

Impact

Successful exploitation of CVE-2026-105216 allows attackers to compromise the confidentiality and integrity of inter-service communication. This vulnerability facilitates the theft of sensitive authentication credentials and tokens, leading to potential unauthorized access to the entire backend infrastructure or associated data stores. Organizations utilizing go-micro in distributed environments are at risk of complete service impersonation and data interception.

Recommendation

Prioritized actions for addressing CVE-2026-105216:

  • Update all deployments of go-micro to version 6.0.0 or later to ensure InsecureSkipVerify is not enabled by default.
  • Review all custom service implementations to verify that InsecureSkipVerify is explicitly set to false when configuring TLS clients.
  • Monitor network traffic logs for unexpected TLS certificate mismatches or unusual gRPC/HTTP traffic patterns directed toward service registries and message brokers.

Immediate actions

Upgrade go-micro dependencies to version 6.0.0 or later

IT Operations 48h

Mitigations

Upgrade go-micro components to version 6.0.0

immediate IT Operations

CVE-2026-105216