Sceawere
Vulnerability Detail
CVE-2026-105216UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
go-micro Improper TLS Certificate Validation
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.4
- Creation Date
- 1d ago
- Vendor
- micro
- Product
- go-micro
- Attack Type
- Improper Certificate Validation
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
go-micro before 6.0.0 contains an improper certificate validation vulnerability that allows network attackers to impersonate services because the shared TLS helper sets InsecureSkipVerify to true by default. Man-in-the-middle attackers can present any certificate to intercept or modify gRPC transport, HTTP and RabbitMQ broker, and Consul or etcd registry traffic, including authentication tokens and credentials.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.4",
"pubDate": "2026-10-04T18:16:34.287Z",
"pubdate": "2026-10-04T18:16:34.287Z",
"executiveSummary": "The go-micro framework, in versions prior to 6.0.0, exhibits a critical security flaw involving improper TLS certificate validation. This vulnerability stems from the default configuration of the shared TLS helper, which initializes the 'InsecureSkipVerify' parameter to 'true'.\nThis configuration effectively disables the verification of the server's certificate chain and hostname during the TLS handshake process. As a result, the system becomes highly susceptible to Man-in-the-Middle (MitM) attacks.\nNetwork-positioned attackers can intercept, inspect, and modify encrypted traffic across various transports, including gRPC, HTTP, and messaging brokers like RabbitMQ. Furthermore, traffic directed toward service registries such as Consul or etcd is also vulnerable.\nThe risk implications are severe, as the compromise allows for the unauthorized exfiltration of sensitive data, including authentication tokens and plaintext credentials transmitted over the network. No specialized authentication or high-level privileges are required for an attacker to initiate this exploitation, provided they have the ability to position themselves within the communication path between the client and the target service.",
"technicalDetails": "The root cause of this vulnerability lies in the default initialization logic within the go-micro TLS helper utility. By setting 'InsecureSkipVerify' to 'true' in the underlying TLS configuration, the library instructs the Go 'crypto/tls' package to bypass the standard validation procedures that verify the authenticity of a remote peer's certificate against a trusted Certificate Authority (CA) or a provided root certificate.\nWhen a service utilizing an affected version of go-micro attempts to establish a connection via TLS—whether for gRPC communication, HTTP requests, or interaction with infrastructure components like RabbitMQ, Consul, or etcd—the client performs no check on the presented certificate. An attacker capable of performing traffic interception (e.g., via ARP spoofing, DNS poisoning, or compromised network infrastructure) can present a self-signed or otherwise fraudulent certificate to the client. The client, relying on the 'InsecureSkipVerify' flag, will accept the malicious certificate without error, establishing an encrypted tunnel with the attacker rather than the legitimate destination.\nThe attack flow follows a predictable pattern: 1) The attacker positions themselves to intercept traffic intended for a go-micro service. 2) The victim service initiates a TLS handshake with what it believes to be a legitimate service or broker. 3) The attacker intercepts this handshake and presents a malicious certificate, which the client accepts due to the improper configuration. 4) The attacker terminates the TLS connection, decrypts the traffic, inspects or modifies it in real-time, and optionally re-encrypts the traffic to forward it to the real destination if necessary to avoid detection.\nThis vulnerability exposes the entire security posture of the microservices architecture. Since go-micro is often used for inter-service authentication (using tokens or shared secrets), a successful MitM attack allows the attacker to capture these credentials. These credentials can then be used to impersonate services, gain unauthorized access to data stores (etcd/Consul), or execute administrative actions on the message broker (RabbitMQ). The lack of certificate validation turns the 'encrypted' transport into a transparent channel for the attacker, effectively nullifying the confidentiality and integrity guarantees provided by TLS. The exposure is total for any network-adjacent attacker, requiring no prior system-level access to the endpoints themselves."
}