External risk intelligence

go-micro Improper Certificate Validation Allows Impersonation

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-105216

The vulnerability exists in a library (go-micro) used for service-to-service communication, including gRPC, HTTP, and broker traffic. While these components are often internal to a network, microservices can be exposed to the internet depending on architecture. Public exposure is possible but not guaranteed as the default deployment pattern for this library's internal TLS helper.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability has been identified in go-micro affecting service-to-service communication. The issue stems from improper certificate validation, which could allow network attackers to impersonate services and intercept sensitive data. The primary concern is confirming whether this technology is in use and, if so, understanding its exposure.

  • Attackers can impersonate services over the network.
  • Affects secure communication between services.
  • Confirm usage and exposure of affected technology.

Attack Path

How an attacker could exploit the issue

An attacker on the network can impersonate a legitimate service by presenting a falsified TLS certificate. This is possible because the shared TLS helper in go-micro incorrectly configures certificate validation to be permissive by default. Such an impersonation allows man-in-the-middle attacks to intercept or alter sensitive network traffic, including authentication tokens and credentials.

  • Network access required.
  • Falsified certificate presented.
  • Intercept or modify traffic.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow man-in-the-middle attackers to intercept or modify traffic between services, potentially exposing sensitive information like authentication tokens and credentials when the affected component is used in a network-exposed service.

  • Network traffic and credentials.
  • Network attackers impersonating services.
  • Interception or modification of communications.

Operational Fix

Recommended remediation, mitigation, and detection steps

The go-micro library's improper certificate validation vulnerability impacts application owners and platform teams responsible for managing inter-service communication. The immediate priority is to inventory all instances of go-micro across the environment, determine their network exposure and business criticality, and identify the accountable teams for remediation planning.

  • Ownership: Application and Platform Teams.
  • Verify first: Identify, assess exposure, and confirm owners.
  • Next action: Plan remediation based on risk assessment.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is go-micro?

go-micro is a Go framework designed for developing distributed systems and microservices. It provides the building blocks for service-to-service communication, including support for gRPC and HTTP, as well as connections to message brokers like RabbitMQ and service registries like Consul or etcd.

What does CWE-295 mean for CVE-2026-105216?

CWE-295 refers to improper certificate validation. In this CVE, the vulnerability means the software's TLS helper incorrectly trusts any certificate presented to it. Instead of verifying that a connection partner is legitimate, it automatically accepts the connection, enabling attackers to pose as a trusted service.

How does an attacker trigger this CVE-2026-105216 vulnerability?

An attacker triggers this by positioning themselves on the network path between two services. By intercepting the communication, they can present a malicious, untrusted certificate. Because the library fails to check certificate authenticity, the connection is accepted. This does not happen if the services are configured to use custom, secure TLS settings that override the default helper.

Do I need to worry about this if my service is internal?

Halo Surface Signal indicates that while these components are often kept internal, the risk depends on your specific architecture. If your network design allows external traffic to reach these service-to-service communication paths, or if the microservices are directly internet-facing, the risk of interception by a network attacker increases significantly.

What should I do first if I run go-micro?

Your first step is to perform an inventory of all applications utilizing versions of go-micro prior to 6.0.0. Once you have identified these instances, assess the network architecture surrounding them to confirm if they handle sensitive traffic or authentication tokens, and coordinate with your platform teams to prioritize updates.

References