OFFLINE
Awaiting data
Security intelligence
CriticalCritical vulnerability

CVE-2026-105218 (CVSS 9.1)

NVD · officialPublished Oct 4, 2026Risk 50/100

gopay before 1.5.119 disables TLS certificate verification in defaultClient() in pkg/xhttp/client.go, allowing man-in-the-middle attackers to impersonate payment provider APIs. Attackers can present any certificate to read merchant credentials, signatures and transaction data, and modify payment, refund and order query responses.

CVSS
9.1
AV:NetworkAC:HighPR:NoneUI:None

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source