PatchSiren

go-pay CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL go-pay CVE published 2026-10-04

CVE-2026-105218

CVE-2026-105218 is a critical vulnerability in the gopay package before version 1.5.119. The vulnerability disables TLS certificate verification in the defaultClient() function in pkg/xhttp/client.go, allowing man-in-the-middle attackers to impersonate payment provider APIs. This could lead to the exposure of merchant credentials, signatures, and transaction data, as well as the modification of payment, r [truncated]