Description
go-micro before 6.0.0 contains an improper certificate validation vulnerability that allows network attackers to impersonate services because the shared TLS helper sets InsecureSkipVerify to true by default. Man-in-the-middle attackers can present any certificate to intercept or modify gRPC transport, HTTP and RabbitMQ broker, and Consul or etcd registry traffic, including authentication tokens and credentials.
Published: 2026-10-04
Score: 9.1 Critical
EPSS: n/a
KEV: No
Impact: Man‑in‑the‑middle impersonation of services
Action: Immediate Patch
AI Analysis

Impact

go‑micro prior to version 6.0.0 includes a TLS helper that unconditionally sets InsecureSkipVerify to true, causing the client to trust any presented certificate. This flaw allows an attacker who can intercept the TLS handshake to supply a forged certificate and then hijack gRPC, HTTP, RabbitMQ, Consul, or etcd traffic. The attacker can read or modify authentication tokens, credentials, and other sensitive data transmitted between micro services, effectively bypassing cryptographic protection.

Affected Systems

All deployments of the micro‑ecc project’s go‑micro library with version numbers below 6.0.0 are affected, including the 5.x release series. Services built with these versions that rely on the default TLS helper—including gRPC, HTTP APIs, RabbitMQ messaging, and Consul or etcd registries—are potentially vulnerable to certificate validation bypass.

Risk and Exploitability

The CVSS v3.1 score of 9.1 indicates critical severity. No EPSS score is publicly available, and the vulnerability has not yet been listed in CISA KEV. The likely attack vector is the network path that inter‑service traffic traverses; an adversary who can observe or inject traffic between micro services can exploit the flaw with no additional privileges or application‑specific knowledge. Given the breadth of traffic that can be compromised, the impact is potentially widespread across a distributed system.

Generated by OpenCVE AI on October 4, 2026 at 18:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade go‑micro to version 6.0.0 or later where the TLS helper enforces proper certificate validation.
  • If an upgrade cannot be performed immediately, modify the shared TLS helper configuration to set InsecureSkipVerify to false and supply a trusted certificate pool that enforces verification.
  • Verify that all micro services using gRPC, HTTP, RabbitMQ, Consul, or etcd are configured with valid certificates and that client‑side certificate verification is enabled.

Generated by OpenCVE AI on October 4, 2026 at 18:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 04 Oct 2026 17:30:00 +0000

Type Values Removed Values Added
Description go-micro before 6.0.0 contains an improper certificate validation vulnerability that allows network attackers to impersonate services because the shared TLS helper sets InsecureSkipVerify to true by default. Man-in-the-middle attackers can present any certificate to intercept or modify gRPC transport, HTTP and RabbitMQ broker, and Consul or etcd registry traffic, including authentication tokens and credentials.
Title go-micro before 6.0.0 Disabled TLS Certificate Verification via tls.Config Helper
First Time appeared Micro-ecc Project
Micro-ecc Project micro-ecc
Weaknesses CWE-295
CPEs cpe:2.3:a:micro-ecc_project:micro-ecc:*:*:*:*:*:*:*:*
Vendors & Products Micro-ecc Project
Micro-ecc Project micro-ecc
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 9.1, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Micro-ecc Project Micro-ecc
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-04T17:09:52.327Z

Reserved: 2026-10-04T13:04:00.478Z

Link: CVE-2026-105216

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-04T18:16:34.287

Modified: 2026-10-04T18:16:34.287

Link: CVE-2026-105216

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-04T19:00:14Z

Weaknesses
  • CWE-295

    Improper Certificate Validation