go-micro before 6.0.0 contains an improper certificate validation vulnerability that allows network attackers to impersonate services because the shared TLS helper sets InsecureSkipVerify to true by default. Man-in-the-middle attackers can present any certificate to intercept or modify gRPC transport, HTTP and RabbitMQ broker, and Consul or etcd registry traffic, including authentication tokens and credentials.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 04 Oct 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | go-micro before 6.0.0 contains an improper certificate validation vulnerability that allows network attackers to impersonate services because the shared TLS helper sets InsecureSkipVerify to true by default. Man-in-the-middle attackers can present any certificate to intercept or modify gRPC transport, HTTP and RabbitMQ broker, and Consul or etcd registry traffic, including authentication tokens and credentials. | |
| Title | go-micro before 6.0.0 Disabled TLS Certificate Verification via tls.Config Helper | |
| First Time appeared |
Micro-ecc Project
Micro-ecc Project micro-ecc |
|
| Weaknesses | CWE-295 | |
| CPEs | cpe:2.3:a:micro-ecc_project:micro-ecc:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Micro-ecc Project
Micro-ecc Project micro-ecc |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-04T17:09:52.327Z
Reserved: 2026-10-04T13:04:00.478Z
Link: CVE-2026-105216
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses