Skip to content
Closed
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -7,13 +7,17 @@
"CVE-2026-105216"
],
"summary": "go-micro disables TLS certificate verification by default",
"details": "go-micro v5.13.0 through v5.30.0 disables TLS certificate verification by default in its shared TLS configuration. The default `Config()` sets `InsecureSkipVerify` to true unless `MICRO_TLS_SECURE=true` is explicitly configured.\nAs a result, applications relying on the default TLS configuration may fail to authenticate the remote endpoint, potentially allowing a network-positioned attacker to perform a man-in-the-middle attack.\nThe affected TLS configuration is used by components including gRPC transport, HTTP and RabbitMQ brokers, and Consul and etcd registry integrations.\nIn v6.0.0, the default was changed to secure certificate verification (`InsecureSkipVerify=false`). Disabling verification now requires the explicit `MICRO_TLS_INSECURE=true` configuration.",
"details": "go-micro `v5.0.0` through `v5.30.0` disables TLS certificate verification by default in multiple client components. In `v5.13.0`, this behavior was centralized in the shared TLS configuration, where `Config()` sets `InsecureSkipVerify` to true unless `MICRO_TLS_SECURE=true` is explicitly configured.\nAs a result, applications relying on the default TLS configuration may fail to authenticate the remote endpoint, potentially allowing a network-positioned attacker to perform a man-in-the-middle attack.\nThe affected TLS configuration is used by components including gRPC transport, HTTP and RabbitMQ brokers, and Consul and etcd registry integrations.\nIn v6.0.0, the default was changed to secure certificate verification (`InsecureSkipVerify=false`). Disabling verification now requires the explicit `MICRO_TLS_INSECURE=true` configuration.",
"severity": [
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
}
],
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
}
],
"affected": [
{
"package": {
Expand Down Expand Up @@ -74,4 +78,4 @@
"github_reviewed_at": null,
"nvd_published_at": "2026-10-04T18:16:34Z"
}
}
}