GPU VulnDB

Database/Control plane, storage & DevOps

go-micro: TLS helper defaults to InsecureSkipVerify, allowing service impersonation

CVSS 9.1CVE-2026-105216Control plane, storage & DevOpscurated

Impact

The shared TLS helper in go-micro sets InsecureSkipVerify to true by default, so every transport built through it accepts any certificate. That covers gRPC service-to-service calls, the HTTP and RabbitMQ broker, and the Consul or etcd registry connections. An on-path attacker can impersonate a service or the registry, read the authentication tokens and credentials that flow over those links, and modify traffic - including registry entries that decide where requests are sent. Where go-micro services run as part of a cluster's control or scheduling path, that is credential theft plus the ability to redirect calls, not just eavesdropping.

Who can reach it

Network attacker on the path between go-micro components, or between a component and its Consul/etcd registry or broker. No credentials required.

What to do

Upgrade go-micro to 6.0.0 or later, which changes the helper default, and rebuild and redeploy every service that links it. Anything that relied on the permissive default needs real CA material configured before the upgrade, or connections will start failing closed. Rotate tokens and credentials that traversed the affected links if you have reason to think the path was untrusted.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.