{"id":"CVE-2026-105216","summary":"go-micro before 6.0.0 Disabled TLS Certificate Verification via tls.Config Helper","details":"go-micro before 6.0.0 contains an improper certificate validation vulnerability that allows network attackers to impersonate services because the shared TLS helper sets InsecureSkipVerify to true by default. Man-in-the-middle attackers can present any certificate to intercept or modify gRPC transport, HTTP and RabbitMQ broker, and Consul or etcd registry traffic, including authentication tokens and credentials.","modified":"2026-10-06T10:30:41.736453833Z","published":"2026-10-04T17:09:52.327Z","database_specific":{"cna_assigner":"VulnCheck","cwe_ids":["CWE-295"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/105xxx/CVE-2026-105216.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/105xxx/CVE-2026-105216.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105216"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/go-micro-before-6.0.0-disabled-tls-certificate-verification-via-tls-config-helper"},{"type":"REPORT","url":"https://github.com/micro/go-micro/issues/2963"},{"type":"FIX","url":"https://github.com/micro/go-micro/commit/c7657f73f45cf839e643db10f28703eeab7299c3"},{"type":"PACKAGE","url":"https://github.com/micro/go-micro"},{"type":"ARTICLE","url":"https://github.com/micro/go-micro/blob/v5.30.0/internal/util/tls/tls.go#L43-L67"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/micro/go-micro","events":[{"introduced":"0"},{"fixed":"c7657f73f45cf839e643db10f28703eeab7299c3"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"6.0.0"}],"source":["AFFECTED_FIELD","DESCRIPTION","REFERENCES"]}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-105216.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"}]}