CRITICAL
micro
CVE published 2026-10-04
CVE-2026-105216
CVE-2026-105216 is a critical vulnerability in go-micro before version 6.0.0, allowing network attackers to impersonate services due to improper certificate validation. The shared TLS helper sets InsecureSkipVerify to true by default, enabling man-in-the-middle attackers to intercept or modify gRPC transport, HTTP and RabbitMQ broker, and Consul or etcd registry traffic, including authentication tokens an [truncated]