Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 05 Oct 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 04 Oct 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Go-pay
Go-pay gopay |
|
| Vendors & Products |
Go-pay
Go-pay gopay |
Sun, 04 Oct 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | gopay before 1.5.119 disables TLS certificate verification in defaultClient() in pkg/xhttp/client.go, allowing man-in-the-middle attackers to impersonate payment provider APIs. Attackers can present any certificate to read merchant credentials, signatures and transaction data, and modify payment, refund and order query responses. | |
| Title | gopay before 1.5.119 Disabled TLS Certificate Verification in xhttp Client | |
| Weaknesses | CWE-295 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-05T14:55:01.904Z
Reserved: 2026-10-04T13:04:00.479Z
Link: CVE-2026-105218
Updated: 2026-10-05T14:50:33.211Z
Status : Received
Published: 2026-10-04T18:16:34.630
Modified: 2026-10-05T15:17:19.340
Link: CVE-2026-105218
No data.
OpenCVE Enrichment
Updated: 2026-10-04T20:48:27Z
