Improper Certificate Validation in go-micro
The go-micro library versions prior to 6.0.0 insecurely configure TLS validation by default, enabling man-in-the-middle attacks to intercept traffic and harvest credentials.
CVE search metadata
CVE search record: CVE-2026-105216. Severity: high. CVSS: 7.4. KEV: no. Product: go-micro (< 6.0.0). Brief: Improper Certificate Validation in go-micro. Brief link: https://feed.craftedsignal.io/briefs/2026-10-go-micro-tls/
The go-micro framework versions before 6.0.0 contain a critical vulnerability where the shared TLS helper defaults the InsecureSkipVerify configuration to true. This default setting bypasses standard X.509 certificate validation, allowing network-adjacent attackers to perform man-in-the-middle (MitM) attacks. By positioning themselves between microservices or between a service and its broker/registry, an attacker can silently intercept, inspect, or modify traffic. The impact is significant, as the vulnerability affects critical communication channels including gRPC, HTTP, RabbitMQ broker traffic, and service registry interactions with Consul or etcd. Successful exploitation provides attackers with the capability to steal authentication tokens and administrative credentials, facilitating further lateral movement or data exfiltration within the microservices environment.
Impact
Successful exploitation of CVE-2026-105216 allows attackers to compromise the confidentiality and integrity of inter-service communication. This vulnerability facilitates the theft of sensitive authentication credentials and tokens, leading to potential unauthorized access to the entire backend infrastructure or associated data stores. Organizations utilizing go-micro in distributed environments are at risk of complete service impersonation and data interception.
Recommendation
Prioritized actions for addressing CVE-2026-105216:
- Update all deployments of go-micro to version 6.0.0 or later to ensure InsecureSkipVerify is not enabled by default.
- Review all custom service implementations to verify that InsecureSkipVerify is explicitly set to false when configuring TLS clients.
- Monitor network traffic logs for unexpected TLS certificate mismatches or unusual gRPC/HTTP traffic patterns directed toward service registries and message brokers.
Immediate actions
Upgrade go-micro dependencies to version 6.0.0 or later
Mitigations
Upgrade go-micro components to version 6.0.0
CVE-2026-105216