CVE-2026-105216 UNKNOWN

CVE-2026-105216

Published: 2026-10-04

Description

go-micro before 6.0.0 contains an improper certificate validation vulnerability that allows network attackers to impersonate services because the shared TLS helper sets InsecureSkipVerify to true by default. Man-in-the-middle attackers can present any certificate to intercept or modify gRPC transport, HTTP and RabbitMQ broker, and Consul or etcd registry traffic, including authentication tokens and credentials.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…