TLS Certificate Verification Flaw in GoPay Payment Processor
CVE-2026-105218

9.1CRITICAL

Key Information:

Vendor

Go-pay

Status
Vendor
CVE Published:
4 October 2026

What is CVE-2026-105218?

The GoPay payment processing system, prior to version 1.5.119, suffers from a critical flaw where TLS certificate verification is disabled in the defaultClient() function within the xhttp client module. This oversight allows malicious actors to execute man-in-the-middle attacks, impersonating payment provider APIs. Consequently, attackers can present forged certificates, gaining access to sensitive merchant credentials, signatures, and transaction details. This vulnerability enables the modification of payment transactions, refunds, and order queries, posing serious risks to the security of financial operations.

Affected Version(s)

gopay 0 < 1.5.119

References

CVSS V4

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Siyang Wu
.