Description
gopay before 1.5.119 disables TLS certificate verification in defaultClient() in pkg/xhttp/client.go, allowing man-in-the-middle attackers to impersonate payment provider APIs. Attackers can present any certificate to read merchant credentials, signatures and transaction data, and modify payment, refund and order query responses.
Published: 2026-10-04
Score: 9.1 Critical
EPSS: n/a
KEV: No
Impact: Man-in-the-Middle
Action: Patch Immediately
AI Analysis

Impact

The vulnerability disables TLS certificate verification in the default HTTP client used by the gopay library. This allows an attacker to act as a man‑in‑the‑middle, presenting any certificate and thereby intercepting merchant credentials, transaction signatures, and other sensitive data. The attacker can also alter payment, refund and order query responses, creating fraudulent transactions or disabling legitimate ones.

Affected Systems

Any application that incorporates the go-pay library version before 1.5.119 is affected. The exposed component is the gopay/xhttp client, which is used in merchant payment integrations to communicate with payment provider APIs.

Risk and Exploitability

The CVSS score is 9.1, indicating a high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The risk is significant because the flaw provides a remote attacker with the ability to interpose and modify traffic over TLS. Exploitation requires the attacker to intercept traffic between the merchant infrastructure and the payment provider, which is feasible in compromised network environments or through DNS hijacking. The vulnerability does not require privileged access and can be abused by attackers with network visibility or control. Due to its severity and the ease of exploitation when certificate checks are disabled, immediate mitigation is recommended.

Generated by OpenCVE AI on October 4, 2026 at 18:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the gopay library to version 1.5.119 or later.
  • Verify that your application does not override TLS verification settings such as InsecureSkipVerify in the HTTP client.
  • If an upgrade is not immediately possible, implement stricter TLS validation by using a custom client that enforces certificate checks and reject any self‑signed or untrusted certificates.

Generated by OpenCVE AI on October 4, 2026 at 18:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 04 Oct 2026 17:30:00 +0000

Type Values Removed Values Added
Description gopay before 1.5.119 disables TLS certificate verification in defaultClient() in pkg/xhttp/client.go, allowing man-in-the-middle attackers to impersonate payment provider APIs. Attackers can present any certificate to read merchant credentials, signatures and transaction data, and modify payment, refund and order query responses.
Title gopay before 1.5.119 Disabled TLS Certificate Verification in xhttp Client
Weaknesses CWE-295
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 9.1, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-04T17:09:53.573Z

Reserved: 2026-10-04T13:04:00.479Z

Link: CVE-2026-105218

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-04T18:16:34.630

Modified: 2026-10-04T18:16:34.630

Link: CVE-2026-105218

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-04T18:30:17Z

Weaknesses
  • CWE-295

    Improper Certificate Validation