CVE-2026-105218

Source
https://cve.org/CVERecord?id=CVE-2026-105218
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-105218.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-105218
Published
2026-10-04T17:09:53Z
Modified
2026-10-06T02:47:20Z
Severity
  • 9.1 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
gopay before 1.5.119 Disabled TLS Certificate Verification in xhttp Client
Details

gopay before 1.5.119 disables TLS certificate verification in defaultClient() in pkg/xhttp/client.go, allowing man-in-the-middle attackers to impersonate payment provider APIs. Attackers can present any certificate to read merchant credentials, signatures and transaction data, and modify payment, refund and order query responses.

Database specific
{
    "cna_assigner":  "VulnCheck",
    "cwe_ids":  [
        "CWE-295"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/105xxx/CVE-2026-105218.json"
}
References

Affected packages

Git / github.com/go-pay/gopay

Affected ranges

Type
GIT
Repo
https://github.com/go-pay/gopay
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "fixed":  "1.5.119"
        }
    ],
    "source":  [
        "AFFECTED_FIELD",
        "DESCRIPTION",
        "REFERENCES"
    ]
}

Affected versions

1.*
1.0.2
1.3.5
1.5.105
1.5.21
1.5.22
Other
latest
v1.*
v1.0
v1.0.0
v1.0.1
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.0.7
v1.0.8
v1.0.9
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.1.5
v1.1.6
v1.1.7
v1.1.8
v1.1.9
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.2.9
v1.3.0
v1.3.1
v1.3.2
v1.3.4
v1.3.6
v1.3.7
v1.3.8
v1.3.9
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.4.6
v1.4.7
v1.4.8
v1.5.1
v1.5.10
v1.5.100
v1.5.101
v1.5.104
v1.5.106
v1.5.107
v1.5.108
v1.5.109
v1.5.11
v1.5.110
v1.5.111
v1.5.112
v1.5.113
v1.5.114
v1.5.115
v1.5.116
v1.5.117
v1.5.118
v1.5.12
v1.5.13
v1.5.14
v1.5.15
v1.5.16
v1.5.17
v1.5.18
v1.5.19
v1.5.2
v1.5.20
v1.5.22
v1.5.23
v1.5.24
v1.5.25
v1.5.26
v1.5.27
v1.5.28
v1.5.29
v1.5.3
v1.5.30
v1.5.31
v1.5.32
v1.5.33
v1.5.34
v1.5.35
v1.5.36
v1.5.37
v1.5.38
v1.5.39
v1.5.4
v1.5.40
v1.5.41
v1.5.42
v1.5.44
v1.5.45
v1.5.46
v1.5.47
v1.5.48
v1.5.49
v1.5.5
v1.5.50
v1.5.51
v1.5.52
v1.5.53
v1.5.54
v1.5.55
v1.5.56
v1.5.57
v1.5.6
v1.5.60
v1.5.61
v1.5.62
v1.5.64
v1.5.65
v1.5.66
v1.5.67
v1.5.68
v1.5.69
v1.5.7
v1.5.71
v1.5.72
v1.5.73
v1.5.74
v1.5.75
v1.5.76
v1.5.78
v1.5.79
v1.5.8
v1.5.80
v1.5.81
v1.5.82
v1.5.83
v1.5.84
v1.5.85
v1.5.86
v1.5.87
v1.5.88
v1.5.89
v1.5.9
v1.5.90
v1.5.91
v1.5.92
v1.5.93
v1.5.95
v1.5.96
v1.5.97
v1.5.98

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-105218.json"