CVE-2026-105218

Summary

gopay before 1.5.119 disables TLS certificate verification in defaultClient() in pkg/xhttp/client.go, allowing man-in-the-middle attackers to impersonate payment provider APIs. Attackers can present any certificate to read merchant credentials, signatures and transaction data, and modify payment, refund and order query responses.

Affected Software

VendorProductVersion RangeStatus
go-paygopay0 < 1.5.119affected

Weaknesses

  • CWE-295: Improper Certificate Validation

References