2026-10-04 17:9CVE-2026-105218VulnCheck
PUBLISHED5.2CWE-295

gopay before 1.5.119 Disabled TLS Certificate Verification in xhttp Client

gopay before 1.5.119 disables TLS certificate verification in defaultClient() in pkg/xhttp/client.go, allowing man-in-the-middle attackers to impersonate payment provider APIs. Attackers can present any certificate to read merchant credentials, signatures and transaction data, and modify payment, refund and order query responses.

Problem type

Affected products

go-pay

gopay

< 1.5.119 - AFFECTED

References

JSON source

https://cveawg.mitre.org/api/cve/CVE-2026-105218
Click to expand
{
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "cveMetadata": {
    "cveId": "CVE-2026-105218",
    "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
    "assignerShortName": "VulnCheck",
    "dateUpdated": "2026-10-04T17:09:53.573Z",
    "dateReserved": "2026-10-04T13:04:00.479Z",
    "datePublished": "2026-10-04T17:09:53.573Z",
    "state": "PUBLISHED"
  },
  "containers": {
    "cna": {
      "providerMetadata": {
        "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "shortName": "VulnCheck",
        "dateUpdated": "2026-10-04T17:09:53.573Z"
      },
      "datePublic": "2026-06-15T00:00:00.000Z",
      "title": "gopay before 1.5.119 Disabled TLS Certificate Verification in xhttp Client",
      "descriptions": [
        {
          "lang": "en",
          "value": "gopay before 1.5.119 disables TLS certificate verification in defaultClient() in pkg/xhttp/client.go, allowing man-in-the-middle attackers to impersonate payment provider APIs. Attackers can present any certificate to read merchant credentials, signatures and transaction data, and modify payment, refund and order query responses."
        }
      ],
      "affected": [
        {
          "vendor": "go-pay",
          "product": "gopay",
          "defaultStatus": "unaffected",
          "versions": [
            {
              "version": "0",
              "status": "affected",
              "versionType": "semver",
              "lessThan": "1.5.119"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "lang": "en",
              "description": "Improper Certificate Validation",
              "cweId": "CWE-295",
              "type": "CWE"
            }
          ]
        }
      ],
      "references": [
        {
          "url": "https://github.com/go-pay/gopay/issues/540",
          "name": "GitHub Issue #540",
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/go-pay/gopay/commit/f6df04fd4f64a2ad2c303ba063b6502bfdd259fd",
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/go-pay/gopay/blob/v1.5.118/pkg/xhttp/client.go#L15-L37",
          "tags": [
            "technical-description"
          ]
        },
        {
          "url": "https://github.com/go-pay/gopay",
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/gopay-before-1.5.119-disabled-tls-certificate-verification-in-xhttp-client",
          "name": "VulnCheck Advisory: gopay before 1.5.119 Disabled TLS Certificate Verification in xhttp Client",
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "metrics": [
        {
          "format": "CVSS"
        },
        {
          "format": "CVSS",
          "cvssV3_1": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "scope": "UNCHANGED",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "availabilityImpact": "NONE",
            "baseScore": 7.4,
            "baseSeverity": "HIGH"
          }
        }
      ],
      "credits": [
        {
          "lang": "en",
          "value": "Siyang Wu",
          "type": "finder"
        }
      ]
    }
  }
}