TLS Certificate Verification Flaw in GoPay Payment Processor
CVE-2026-105218
9.1CRITICAL
What is CVE-2026-105218?
The GoPay payment processing system, prior to version 1.5.119, suffers from a critical flaw where TLS certificate verification is disabled in the defaultClient() function within the xhttp client module. This oversight allows malicious actors to execute man-in-the-middle attacks, impersonating payment provider APIs. Consequently, attackers can present forged certificates, gaining access to sensitive merchant credentials, signatures, and transaction details. This vulnerability enables the modification of payment transactions, refunds, and order queries, posing serious risks to the security of financial operations.
Affected Version(s)
gopay 0 < 1.5.119
