CVE-2026-105218 - gopay before 1.5.119 Disabled TLS Certificate Verification in xhttp Client
Brief
CVE ID : CVE-2026-105218
Published : Oct. 4, 2026, 6:16 p. m.
- 1 hour, 15 minutes ago
Description : gopay before 1.
- 119 disables TLS certificate verification in defaultClient() in pkg/xhttp/client. go, allowing man-in-the-middle attackers to impersonate payment provider APIs. Attackers can present any certificate to read merchant credentials, signatures and transaction data, and modify payment, refund and order query responses.
Severity: 9.1
- CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
