High severity7.4NVD Advisory· Published Oct 4, 2026
CVE-2026-105218
CVE-2026-105218
Description
gopay before 1.5.119 disables TLS certificate verification in defaultClient() in pkg/xhttp/client.go, allowing man-in-the-middle attackers to impersonate payment provider APIs. Attackers can present any certificate to read merchant credentials, signatures and transaction data, and modify payment, refund and order query responses.
Affected products
1Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.