Skip to content

Update GHSA-p6q5-cmw8-pqqg.json details and severity - #10176

Closed
ranjiGT wants to merge 2 commits into
github:ranjiGT-GHSA-p6q5-cmw8-pqqgfrom
ranjiGT:patch-1
Closed

ranjiGT wants to merge 2 commits into
github:ranjiGT-GHSA-p6q5-cmw8-pqqgfrom
ranjiGT:patch-1

Conversation

@ranjiGT

@ranjiGT ranjiGT commented Oct 4, 2026

Copy link
Copy Markdown

Summary

Follow-up changes for GHSA-p6q5-cmw8-pqqg based on review feedback.

Changes

  • Correct the affected go-micro.dev/v5 range to start at v5.0.0.
    • Earlier v5 releases already use InsecureSkipVerify: true directly in multiple production components.
    • v5.13.0 introduced the shared TLS configuration rather than introducing the vulnerable behavior itself.
  • Clarify the advisory description to distinguish the existing insecure TLS behavior from its centralization in the shared TLS helper in v5.13.0.
  • Restore the existing CVSS v3.1 vector so consumers that do not support CVSS v4 retain severity information.
  • Retain the corrected CVSS v4 vector.

Validation

Verified the affected behavior against upstream go-micro release tags and confirmed that InsecureSkipVerify: true is present in production code in v5.0.0 and subsequent v5 releases.

Context

These changes address review feedback on the original advisory improvement and improve the accuracy of the affected version range and severity metadata.

Copilot AI balanced review requested due to automatic review settings October 4, 2026 21:09

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The machine-readable affected range remains at 5.13.0 and the description contains duplicated, malformed text.

Review effort: Balanced
Findings: 1 High severity · 1 Low severity

Open (2)
What changed in this PR

Updates the advisory’s TLS vulnerability description and severity metadata.

Changes:

  • Expands the documented affected versions.
  • Restores CVSS v3.1 while retaining CVSS v4.
File Description
GHSA-p6q5-cmw8-pqqg.json Updates advisory details and severity vectors.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

],
"summary": "go-micro disables TLS certificate verification by default",
"details": "go-micro v5.13.0 through v5.30.0 disables TLS certificate verification by default in its shared TLS configuration. The default `Config()` sets `InsecureSkipVerify` to true unless `MICRO_TLS_SECURE=true` is explicitly configured.\nAs a result, applications relying on the default TLS configuration may fail to authenticate the remote endpoint, potentially allowing a network-positioned attacker to perform a man-in-the-middle attack.\nThe affected TLS configuration is used by components including gRPC transport, HTTP and RabbitMQ brokers, and Consul and etcd registry integrations.\nIn v6.0.0, the default was changed to secure certificate verification (`InsecureSkipVerify=false`). Disabling verification now requires the explicit `MICRO_TLS_INSECURE=true` configuration.",
"details": "go-micro `v5.0.0` through `v5.30.0` disables TLS certificate verification by default in multiple client components. In `v5.13.0`, this behavior was centralized in the shared TLS configuration, where `Config()` sets InsecureSkipVerify to true unless ´MICRO_TLS_SECURE=true´ is explicitly configured. The default `Config()` sets `InsecureSkipVerify` to true unless `MICRO_TLS_SECURE=true` is explicitly configured.\nAs a result, applications relying on the default TLS configuration may fail to authenticate the remote endpoint, potentially allowing a network-positioned attacker to perform a man-in-the-middle attack.\nThe affected TLS configuration is used by components including gRPC transport, HTTP and RabbitMQ brokers, and Consul and etcd registry integrations.\nIn v6.0.0, the default was changed to secure certificate verification (`InsecureSkipVerify=false`). Disabling verification now requires the explicit `MICRO_TLS_INSECURE=true` configuration.",
Comment thread advisories/unreviewed/2026/10/GHSA-p6q5-cmw8-pqqg/GHSA-p6q5-cmw8-pqqg.json Outdated
Updated details for CVE-2026-105216 to clarify TLS certificate verification behavior changes in go-micro.

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
@ranjiGT

ranjiGT commented Oct 4, 2026

Copy link
Copy Markdown
Author

Closing this follow-up PR because GitHub Advisory Database only allows one pending improvement per advisory. The review fixes have now been pushed directly to #10175.

@ranjiGT ranjiGT closed this Oct 4, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants