CRITICAL
go-pay
CVE published 2026-10-04
CVE-2026-105218
CVE-2026-105218 is a critical vulnerability in the gopay package before version 1.5.119. The vulnerability disables TLS certificate verification in the defaultClient() function in pkg/xhttp/client.go, allowing man-in-the-middle attackers to impersonate payment provider APIs. This could lead to the exposure of merchant credentials, signatures, and transaction data, as well as the modification of payment, r [truncated]