CVE-2026-105218
Received Received - Intake

Gopay TLS Certificate Verification Bypass

Vulnerability report for CVE-2026-105218, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-04

Last updated on: 2026-10-04

Assigner: VulnCheck

Description

gopay before 1.5.119 disables TLS certificate verification in defaultClient() in pkg/xhttp/client.go, allowing man-in-the-middle attackers to impersonate payment provider APIs. Attackers can present any certificate to read merchant credentials, signatures and transaction data, and modify payment, refund and order query responses.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-04
Last Modified
2026-10-04
Generated
2026-10-04
AI Q&A
2026-10-04
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
go-pay gopay to 1.5.119 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-295 The product does not validate, or incorrectly validates, a certificate.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-105218 is a vulnerability in gopay versions before 1.5.119 where TLS certificate verification is disabled by default in the HTTP client. This allows man-in-the-middle attackers to impersonate payment provider APIs, intercept sensitive data like merchant credentials and transaction details, and modify payment responses.

Detection Guidance

Check if your GoPay version is below 1.5.119 by running 'go list -m github.com/go-pay/gopay'. Inspect code for 'InsecureSkipVerify: true' in TLS config. Monitor network traffic for unencrypted or modified payment API calls.

Impact Analysis

Attackers can read or alter payment data, including credentials, signatures, and transaction information. They may modify payment responses, refunds, or order queries, leading to financial loss or data breaches. Systems using gopay before 1.5.119 are at risk.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR's data protection requirements and HIPAA's safeguards for protected health information. Non-compliance may result in legal penalties and reputational damage.

Mitigation Strategies

Upgrade to GoPay version 1.5.119 or later. If using sandbox/self-signed certificates, explicitly set 'InsecureSkipVerify: true' in TLS config after client creation. Review and secure hardcoded credentials in payment methods.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105218. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart