
go-micro's new CVE names a major-version upgrade as the only fix for TLS verification being off by default. The one-variable mitigation sits in the lines the record links to. No exploitation reported. https://severitydaily.com/go-micro-cve-2026-105216-insecureskipverify-default-only-fix-v6/
