Impact
go‑micro prior to version 6.0.0 includes a TLS helper that unconditionally sets InsecureSkipVerify to true, causing the client to trust any presented certificate. This flaw allows an attacker who can intercept the TLS handshake to supply a forged certificate and then hijack gRPC, HTTP, RabbitMQ, Consul, or etcd traffic. The attacker can read or modify authentication tokens, credentials, and other sensitive data transmitted between micro services, effectively bypassing cryptographic protection.
Affected Systems
All deployments of the micro‑ecc project’s go‑micro library with version numbers below 6.0.0 are affected, including the 5.x release series. Services built with these versions that rely on the default TLS helper—including gRPC, HTTP APIs, RabbitMQ messaging, and Consul or etcd registries—are potentially vulnerable to certificate validation bypass.
Risk and Exploitability
The CVSS v3.1 score of 9.1 indicates critical severity. No EPSS score is publicly available, and the vulnerability has not yet been listed in CISA KEV. The likely attack vector is the network path that inter‑service traffic traverses; an adversary who can observe or inject traffic between micro services can exploit the flaw with no additional privileges or application‑specific knowledge. Given the breadth of traffic that can be compromised, the impact is potentially widespread across a distributed system.
OpenCVE Enrichment