www.vulncheck.com Go Micro Framework Exposes Services to MITM Attacks Due to Insecure TLS Config
Article Content
- •Go-micro's default TLS setting is insecure, allowing MITM attacks.
- •Services not using MICRO_TLS_SECURE=true are at risk of data interception.
- •The vulnerability has been acknowledged but remains unpatched due to compatibility concerns.
The go-micro framework, prior to version 6.0.0, has a default TLS configuration that disables certificate verification for gRPC and HTTP communications, making it vulnerable to man-in-the-middle (MITM) attacks. This issue is acknowledged in the code with a SECURITY WARNING and DEPRECATION NOTICE, but the default setting remains unchanged for backward compatibility. Services using go-micro without explicitly setting the MICRO_TLS_SECURE=true option will transmit data over unverified TLS, allowing network-adjacent attackers to intercept and modify service-to-service traffic. The recommended actions are to change the default configuration or invert the opt-in requirement to enhance security. A full technical report is available upon request.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Common questions
Which versions of go-micro are affected?
What should I do if I'm using go-micro?
Is there a patch available?
Continue Reading
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…