Skip to main content
HIGH

CVE-2026-105216

go-micro before 6.0.0 Disabled TLS Certificate Verification via tls.Config Helper

CVSS v3

7.4

HIGH

EPSS Score

—

exploit probability

CISA KEV

No

known exploited

Exploitation

—

SSVC status

Description

go-micro before 6.0.0 contains an improper certificate validation vulnerability that allows network attackers to impersonate services because the shared TLS helper sets InsecureSkipVerify to true by default. Man-in-the-middle attackers can present any certificate to intercept or modify gRPC transport, HTTP and RabbitMQ broker, and Consul or etcd registry traffic, including authentication tokens and credentials.

Technical details

CVSS v3 Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Published
2026-10-04
Last Modified
2026-10-04

Frequently asked questions

What is CVE-2026-105216?

go-micro before 6.0.0 contains an improper certificate validation vulnerability that allows network attackers to impersonate services because the shared TLS helper sets InsecureSkipVerify to true by default. Man-in-the-middle attackers can present any certificate to intercept or modify gRPC transport, HTTP and RabbitMQ broker, and Consul or etcd registry traffic, including authentication tokens and credentials.

Is CVE-2026-105216 actively exploited?

Active exploitation of CVE-2026-105216 has not been confirmed.

What is the CVSS score for CVE-2026-105216?

CVE-2026-105216 has a CVSS v3 base score of 7.4 (HIGH severity), with vector string CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N.

Is CVE-2026-105216 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 50 free checks/month · Free API key