Impact
The vulnerability disables TLS certificate verification in the default HTTP client used by the gopay library. This allows an attacker to act as a man‑in‑the‑middle, presenting any certificate and thereby intercepting merchant credentials, transaction signatures, and other sensitive data. The attacker can also alter payment, refund and order query responses, creating fraudulent transactions or disabling legitimate ones.
Affected Systems
Any application that incorporates the go-pay library version before 1.5.119 is affected. The exposed component is the gopay/xhttp client, which is used in merchant payment integrations to communicate with payment provider APIs.
Risk and Exploitability
The CVSS score is 9.1, indicating a high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The risk is significant because the flaw provides a remote attacker with the ability to interpose and modify traffic over TLS. Exploitation requires the attacker to intercept traffic between the merchant infrastructure and the payment provider, which is feasible in compromised network environments or through DNS hijacking. The vulnerability does not require privileged access and can be abused by attackers with network visibility or control. Due to its severity and the ease of exploitation when certificate checks are disabled, immediate mitigation is recommended.
OpenCVE Enrichment