Database/Control plane, storage & DevOps
go-micro: TLS helper defaults to InsecureSkipVerify, allowing service impersonation
Impact
The shared TLS helper in go-micro sets InsecureSkipVerify to true by default, so every transport built through it accepts any certificate. That covers gRPC service-to-service calls, the HTTP and RabbitMQ broker, and the Consul or etcd registry connections. An on-path attacker can impersonate a service or the registry, read the authentication tokens and credentials that flow over those links, and modify traffic - including registry entries that decide where requests are sent. Where go-micro services run as part of a cluster's control or scheduling path, that is credential theft plus the ability to redirect calls, not just eavesdropping.
Who can reach it
Network attacker on the path between go-micro components, or between a component and its Consul/etcd registry or broker. No credentials required.
What to do
Upgrade go-micro to 6.0.0 or later, which changes the helper default, and rebuild and redeploy every service that links it. Anything that relied on the permissive default needs real CA material configured before the upgrade, or connections will start failing closed. Rotate tokens and credentials that traversed the affected links if you have reason to think the path was untrusted.
References
Related entries
- MsQuic: QUIC clients on the OpenSSL backend do not verify the server certificate hostnameCVE-2026-105794 · MsQuic (OpenSSL/QuicTLS client certificate hostname verification)Critical
- Grafana MCP Server: caller-controlled X-Grafana-URL header turns grafana_api_request into a full SSRF primitiveCVE-2026-19516 · mcp-grafana (Grafana MCP Server, X-Grafana-URL destination control)Critical
- Apache CloudStack Proxmox extension (cross-tenant instance access): The extension keys CloudStack instances to ProxmoxCVE-2026-25199 · Apache CloudStack Proxmox extension (cross-tenant instance access)Critical
- BACnet Stack open-source C library (bacnet-stack) embedded in third-party controllers and gateways: A runCVE-2026-41475 · BACnet Stack open-source C library (bacnet-stack) embedded in third-party controllers and gatewaysCritical
- Ceph Monitor: any read-only CephX user can dump the config-key store, including cephadm's cluster-wide SSH keyCVE-2026-50152 · Ceph Monitor (MMonSubscribe config-key store authorization)Critical
- Apache Airflow FAB provider: Azure AD id_token issuer and audience unchecked, any tenant can log inCVE-2026-75156 · Apache Airflow FAB provider (Azure AD OAuth id_token issuer/audience validation)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.