Sceawere
Vulnerability Detail
CVE-2026-105218UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Gopay TLS Verification Bypass Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.4
- Creation Date
- 1d ago
- Vendor
- go-pay
- Product
- gopay
- Attack Type
- Improper Certificate Validation
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
gopay before 1.5.119 disables TLS certificate verification in defaultClient() in pkg/xhttp/client.go, allowing man-in-the-middle attackers to impersonate payment provider APIs. Attackers can present any certificate to read merchant credentials, signatures and transaction data, and modify payment, refund and order query responses.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.4",
"pubDate": "2026-10-04T18:16:34.630Z",
"pubdate": "2026-10-04T18:16:34.630Z",
"executiveSummary": "The Go-based library 'gopay' contains a critical security vulnerability involving the improper implementation of Transport Layer Security (TLS) certificate validation. Identified in the defaultClient() function within pkg/xhttp/client.go, the flaw allows the client to establish encrypted connections without verifying the identity of the remote server. This failure to validate server-side certificates facilitates Man-in-the-Middle (MitM) attacks, enabling adversaries to intercept or manipulate sensitive traffic between the application and payment provider APIs.\nThe impact of this vulnerability is severe, as it compromises the confidentiality and integrity of financial transactions. An attacker positioned in the network path can impersonate legitimate payment service providers, harvest merchant credentials, capture digital signatures, and intercept transaction data. Furthermore, the attacker possesses the capability to modify request/response payloads, allowing for the alteration of payment outcomes, refund statuses, and order query results. The vulnerability affects all versions of gopay prior to 1.5.119, posing a substantial risk to any merchant platform utilizing the library for payment processing without external validation layers.",
"technicalDetails": "The root cause of this vulnerability lies in the insecure configuration of the http.Transport object within the defaultClient() function in pkg/xhttp/client.go. By explicitly setting the TLSClientConfig's InsecureSkipVerify field to true, the library instructs the underlying Go 'crypto/tls' package to ignore certificate chain verification. Consequently, the client accepts any certificate presented by a remote host, regardless of its validity, expiration, or provenance, effectively bypassing the cryptographic protections intended to prevent impersonation during the TLS handshake process.\nExploitation requires the attacker to occupy a position that allows for interception of the network traffic, such as a compromised local network, a rogue Wi-Fi access point, or a compromised upstream gateway. Once a MitM position is established, the following attack flow ensues: 1) The client attempts to communicate with the legitimate payment API. 2) The attacker intercepts the request and terminates the TLS connection using an arbitrary or self-signed certificate. 3) Because InsecureSkipVerify is enabled, the gopay client validates the attacker's malicious certificate, establishing a secure tunnel directly with the attacker. 4) The attacker decrypts the traffic, logs sensitive merchant credentials, and captures transaction data. 5) The attacker then forwards the request to the real payment provider (or sends a forged response to the client), allowing for the modification of transaction data, refund requests, or order query responses before they reach the intended recipient.\nThis vulnerability is present in versions of the library prior to 1.5.119. Exploitation does not require authentication or elevated privileges, as it occurs at the transport layer of the communication stack. The exposure is limited to network segments where the traffic is routed through an adversary-controlled point. Post-exploitation impact includes financial loss due to unauthorized payment modification, data exfiltration of sensitive merchant credentials, and potential systemic integrity failure of the merchant's financial reporting and payment confirmation systems."
}