CVE-2026-105218 UNKNOWN

CVE-2026-105218

Published: 2026-10-04

Description

gopay before 1.5.119 disables TLS certificate verification in defaultClient() in pkg/xhttp/client.go, allowing man-in-the-middle attackers to impersonate payment provider APIs. Attackers can present any certificate to read merchant credentials, signatures and transaction data, and modify payment, refund and order query responses.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…