Description
go-micro before 6.0.0 contains an improper certificate validation vulnerability that allows network attackers to impersonate services because the shared TLS helper sets InsecureSkipVerify to true by default. Man-in-the-middle attackers can present any certificate to intercept or modify gRPC transport, HTTP and RabbitMQ broker, and Consul or etcd registry traffic, including authentication tokens and credentials.
Published: 2026-10-04
Score: 9.1 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 04 Oct 2026 17:30:00 +0000

Type Values Removed Values Added
Description go-micro before 6.0.0 contains an improper certificate validation vulnerability that allows network attackers to impersonate services because the shared TLS helper sets InsecureSkipVerify to true by default. Man-in-the-middle attackers can present any certificate to intercept or modify gRPC transport, HTTP and RabbitMQ broker, and Consul or etcd registry traffic, including authentication tokens and credentials.
Title go-micro before 6.0.0 Disabled TLS Certificate Verification via tls.Config Helper
First Time appeared Micro-ecc Project
Micro-ecc Project micro-ecc
Weaknesses CWE-295
CPEs cpe:2.3:a:micro-ecc_project:micro-ecc:*:*:*:*:*:*:*:*
Vendors & Products Micro-ecc Project
Micro-ecc Project micro-ecc
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 9.1, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Micro-ecc Project Micro-ecc
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-04T17:09:52.327Z

Reserved: 2026-10-04T13:04:00.478Z

Link: CVE-2026-105216

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-04T18:16:34.287

Modified: 2026-10-04T18:16:34.287

Link: CVE-2026-105216

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-04T19:00:14Z

Weaknesses