{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/go-micro/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:go-micro:go-micro:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.4,"id":"CVE-2026-105216"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["go-micro (\u003c 6.0.0)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","tls","mitm","go-micro"],"_cs_type":"advisory","_cs_vendors":["go-micro"],"content_html":"\u003cp\u003eThe go-micro framework versions before 6.0.0 contain a critical vulnerability where the shared TLS helper defaults the InsecureSkipVerify configuration to true. This default setting bypasses standard X.509 certificate validation, allowing network-adjacent attackers to perform man-in-the-middle (MitM) attacks. By positioning themselves between microservices or between a service and its broker/registry, an attacker can silently intercept, inspect, or modify traffic. The impact is significant, as the vulnerability affects critical communication channels including gRPC, HTTP, RabbitMQ broker traffic, and service registry interactions with Consul or etcd. Successful exploitation provides attackers with the capability to steal authentication tokens and administrative credentials, facilitating further lateral movement or data exfiltration within the microservices environment.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-105216 allows attackers to compromise the confidentiality and integrity of inter-service communication. This vulnerability facilitates the theft of sensitive authentication credentials and tokens, leading to potential unauthorized access to the entire backend infrastructure or associated data stores. Organizations utilizing go-micro in distributed environments are at risk of complete service impersonation and data interception.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for addressing CVE-2026-105216:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate all deployments of go-micro to version 6.0.0 or later to ensure InsecureSkipVerify is not enabled by default.\u003c/li\u003e\n\u003cli\u003eReview all custom service implementations to verify that InsecureSkipVerify is explicitly set to false when configuring TLS clients.\u003c/li\u003e\n\u003cli\u003eMonitor network traffic logs for unexpected TLS certificate mismatches or unusual gRPC/HTTP traffic patterns directed toward service registries and message brokers.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-04T18:54:09Z","date_published":"2026-10-04T18:54:09Z","id":"https://feed.craftedsignal.io/briefs/2026-10-go-micro-tls/","summary":"The go-micro library versions prior to 6.0.0 insecurely configure TLS validation by default, enabling man-in-the-middle attacks to intercept traffic and harvest credentials.","title":"Improper Certificate Validation in go-micro","url":"https://feed.craftedsignal.io/briefs/2026-10-go-micro-tls/"}],"language":"en","title":"CraftedSignal Threat Feed - Go-Micro","version":"https://jsonfeed.org/version/1.1"}