Skip to content
Go Micro Framework Exposes Services to MITM Attacks Due to Insecure TLS Config

Go Micro Framework Exposes Services to MITM Attacks Due to Insecure TLS Config

First seen 4 Oct 2026, 21:02 UTC •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 4, 2026 at 22:01 UTC
  • •Go-micro's default TLS setting is insecure, allowing MITM attacks.
  • •Services not using MICRO_TLS_SECURE=true are at risk of data interception.
  • •The vulnerability has been acknowledged but remains unpatched due to compatibility concerns.

The go-micro framework, prior to version 6.0.0, has a default TLS configuration that disables certificate verification for gRPC and HTTP communications, making it vulnerable to man-in-the-middle (MITM) attacks. This issue is acknowledged in the code with a SECURITY WARNING and DEPRECATION NOTICE, but the default setting remains unchanged for backward compatibility. Services using go-micro without explicitly setting the MICRO_TLS_SECURE=true option will transmit data over unverified TLS, allowing network-adjacent attackers to intercept and modify service-to-service traffic. The recommended actions are to change the default configuration or invert the opt-in requirement to enhance security. A full technical report is available upon request.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-04
Vulnerability disclosed
The go-micro framework's insecure TLS configuration was publicly disclosed, exposing services to MITM attacks.
github.com
2026-10-04
Advisory published
Vulncheck published an advisory detailing the TLS certificate verification issue in go-micro versions before 6.0.0.
www.vulncheck.com

More articles in this cluster (2)

Common questions

Which versions of go-micro are affected?
All versions of go-micro prior to 6.0.0 are affected by the insecure TLS configuration.
What should I do if I'm using go-micro?
Ensure that you set the MICRO_TLS_SECURE=true option to secure your service-to-service communications.
Is there a patch available?
No patch is currently available; the vulnerability is acknowledged but remains unaddressed due to backward compatibility concerns.