← Back to feed
Vulnerabilities & PatchesEmerging1 sourceOct 4, 2026 · 18:16via CVEFeed

CVE-2026-105218 - gopay before 1.5.119 Disabled TLS Certificate Verification in xhttp Client

Brief

CVE ID : CVE-2026-105218

Published : Oct. 4, 2026, 6:16 p. m.

  • 1 hour, 15 minutes ago

Description : gopay before 1.

  • 119 disables TLS certificate verification in defaultClient() in pkg/xhttp/client. go, allowing man-in-the-middle attackers to impersonate payment provider APIs. Attackers can present any certificate to read merchant credentials, signatures and transaction data, and modify payment, refund and order query responses.

Severity: 9.1

  • CRITICAL

Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Read more on CVEFeed→