<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Go-Micro - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/go-micro/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sun, 04 Oct 2026 18:54:09 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/go-micro/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Improper Certificate Validation in go-micro</title><link>https://feed.craftedsignal.io/briefs/2026-10-go-micro-tls/</link><pubDate>Sun, 04 Oct 2026 18:54:09 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-go-micro-tls/</guid><description>The go-micro library versions prior to 6.0.0 insecurely configure TLS validation by default, enabling man-in-the-middle attacks to intercept traffic and harvest credentials.</description><content:encoded><![CDATA[<p>The go-micro framework versions before 6.0.0 contain a critical vulnerability where the shared TLS helper defaults the InsecureSkipVerify configuration to true. This default setting bypasses standard X.509 certificate validation, allowing network-adjacent attackers to perform man-in-the-middle (MitM) attacks. By positioning themselves between microservices or between a service and its broker/registry, an attacker can silently intercept, inspect, or modify traffic. The impact is significant, as the vulnerability affects critical communication channels including gRPC, HTTP, RabbitMQ broker traffic, and service registry interactions with Consul or etcd. Successful exploitation provides attackers with the capability to steal authentication tokens and administrative credentials, facilitating further lateral movement or data exfiltration within the microservices environment.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of CVE-2026-105216 allows attackers to compromise the confidentiality and integrity of inter-service communication. This vulnerability facilitates the theft of sensitive authentication credentials and tokens, leading to potential unauthorized access to the entire backend infrastructure or associated data stores. Organizations utilizing go-micro in distributed environments are at risk of complete service impersonation and data interception.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for addressing CVE-2026-105216:</p>
<ul>
<li>Update all deployments of go-micro to version 6.0.0 or later to ensure InsecureSkipVerify is not enabled by default.</li>
<li>Review all custom service implementations to verify that InsecureSkipVerify is explicitly set to false when configuring TLS clients.</li>
<li>Monitor network traffic logs for unexpected TLS certificate mismatches or unusual gRPC/HTTP traffic patterns directed toward service registries and message brokers.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>tls</category><category>mitm</category><category>go-micro</category></item></channel></rss>