CVE-2026-105218 PUBLISHED

gopay before 1.5.119 Disabled TLS Certificate Verification in xhttp Client

Assigner: VulnCheck
Reserved: 04.10.2026 Published: 04.10.2026 Updated: 05.10.2026

gopay before 1.5.119 disables TLS certificate verification in defaultClient() in pkg/xhttp/client.go, allowing man-in-the-middle attackers to impersonate payment provider APIs. Attackers can present any certificate to read merchant credentials, signatures and transaction data, and modify payment, refund and order query responses.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
CVSS Score: 9.1

Product Status

Vendor go-pay
Product gopay
Versions Default: unaffected
  • affected from 0 to 1.5.119 (excl.)

Credits

  • Siyang Wu finder

References

Problem Types

  • Improper Certificate Validation CWE