Skip to content

[GHSA-p6q5-cmw8-pqqg] go-micro before 6.0.0 contains an improper certificate... - #10175

Open
ranjiGT wants to merge 1 commit into
ranjiGT/advisory-improvement-10175from
ranjiGT-GHSA-p6q5-cmw8-pqqg
Open

ranjiGT wants to merge 1 commit into
ranjiGT/advisory-improvement-10175from
ranjiGT-GHSA-p6q5-cmw8-pqqg

Conversation

@ranjiGT

@ranjiGT ranjiGT commented Oct 4, 2026 •

Copy link
Copy Markdown

Updates

  • Affected products
  • CVSS v3
  • CVSS v4
  • Description
  • References
  • Source code location
  • Summary

Comments
Adds missing Go package and affected-version metadata based on upstream release history. go-micro.dev/v5 first contains the insecure-by-default shared TLS configuration in v5.13.0, with InsecureSkipVerify=true unless MICRO_TLS_SECURE=true is set. This behavior remains present through v5.30.0. In v6.0.0 the project changes to secure-by-default certificate verification, but v6 uses the separate Go module path go-micro.dev/v6, so no patched version is specified for go-micro.dev/v5. Also adds the upstream source-code location and clarifies the vulnerability description and remediation.

Copilot AI balanced review requested due to automatic review settings October 4, 2026 20:43
@github-actions
github-actions Bot changed the base branch from main to ranjiGT/advisory-improvement-10175 October 4, 2026 20:43

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The affected ranges omit vulnerable releases and module paths, while the documented CVSS v3 vector is removed.

Review effort: Balanced
Findings: 2 Medium severity

Open (2)
What changed in this PR

Updates GHSA-p6q5-cmw8-pqqg with Go package metadata, revised vulnerability details, severity, and references.

Changes:

  • Adds affected-version metadata for go-micro.dev/v5.
  • Revises CVSS v4, summary, details, and upstream references.
File Description
advisories/​unreviewed/​2026/​10/​GHSA-p6q5-cmw8-pqqg/​GHSA-p6q5-cmw8-pqqg.json Expands advisory metadata and affected-version information.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants