Repository navigation
Conversation
Contributor
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The machine-readable affected range remains at 5.13.0 and the description contains duplicated, malformed text.
Review effort: Balanced
Findings: 1
Open (2)
What changed in this PR
Updates the advisory’s TLS vulnerability description and severity metadata.
Changes:
- Expands the documented affected versions.
- Restores CVSS v3.1 while retaining CVSS v4.
| File | Description |
|---|---|
GHSA-p6q5-cmw8-pqqg.json |
Updates advisory details and severity vectors. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| ], | ||
| "summary": "go-micro disables TLS certificate verification by default", | ||
| "details": "go-micro v5.13.0 through v5.30.0 disables TLS certificate verification by default in its shared TLS configuration. The default `Config()` sets `InsecureSkipVerify` to true unless `MICRO_TLS_SECURE=true` is explicitly configured.\nAs a result, applications relying on the default TLS configuration may fail to authenticate the remote endpoint, potentially allowing a network-positioned attacker to perform a man-in-the-middle attack.\nThe affected TLS configuration is used by components including gRPC transport, HTTP and RabbitMQ brokers, and Consul and etcd registry integrations.\nIn v6.0.0, the default was changed to secure certificate verification (`InsecureSkipVerify=false`). Disabling verification now requires the explicit `MICRO_TLS_INSECURE=true` configuration.", | ||
| "details": "go-micro `v5.0.0` through `v5.30.0` disables TLS certificate verification by default in multiple client components. In `v5.13.0`, this behavior was centralized in the shared TLS configuration, where `Config()` sets InsecureSkipVerify to true unless ´MICRO_TLS_SECURE=true´ is explicitly configured. The default `Config()` sets `InsecureSkipVerify` to true unless `MICRO_TLS_SECURE=true` is explicitly configured.\nAs a result, applications relying on the default TLS configuration may fail to authenticate the remote endpoint, potentially allowing a network-positioned attacker to perform a man-in-the-middle attack.\nThe affected TLS configuration is used by components including gRPC transport, HTTP and RabbitMQ brokers, and Consul and etcd registry integrations.\nIn v6.0.0, the default was changed to secure certificate verification (`InsecureSkipVerify=false`). Disabling verification now requires the explicit `MICRO_TLS_INSECURE=true` configuration.", |
Updated details for CVE-2026-105216 to clarify TLS certificate verification behavior changes in go-micro. Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Author
|
Closing this follow-up PR because GitHub Advisory Database only allows one pending improvement per advisory. The review fixes have now been pushed directly to #10175. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.


Summary
Follow-up changes for
GHSA-p6q5-cmw8-pqqgbased on review feedback.Changes
go-micro.dev/v5range to start atv5.0.0.InsecureSkipVerify: truedirectly in multiple production components.v5.13.0introduced the shared TLS configuration rather than introducing the vulnerable behavior itself.v5.13.0.Validation
Verified the affected behavior against upstream
go-microrelease tags and confirmed thatInsecureSkipVerify: trueis present in production code inv5.0.0and subsequent v5 releases.Context
These changes address review feedback on the original advisory improvement and improve the accuracy of the affected version range and severity metadata.