Back Redpacketsecurity CVE Alert: CVE-2026-105218 – go-pay
gopay before 1.5.119 disables TLS certificate verification in defaultClient() in pkg/xhttp/client.go, allowing man-in-the-middle attackers to impersonate payment provider APIs. Attackers can present any certificate to read merchant credentials, signatures and transaction data, and modify payment, refund and order query responses.
**Risk verdict:** Treat this as a high-impact payment-integrity risk; no KEV, SSVC, PoC or EPSS data was supplied, so active exploitation and urgency cannot be confirmed.
**Why this matters:** A successful interception could expose merchant credentials and transaction data, and allow payment or refund responses to be altered. This creates a realistic risk of financial loss, fraudulent activity and difficult-to-reconcile records.
**Most likely attack path:** An attacker must be able to intercept or influence the network connection, such as through a compromised network path or malicious proxy; this is a significant precondition. No privileges or user interaction are required once that position exists. The affected impact is confined to the vulnerable application’s scope, but could still undermine transactions it processes.
**Who is most exposed:** Prioritise services using this Go payment library to communicate with payment-provider APIs, particularly merchant backends and transaction-processing workloads on untrusted or shared networks.
Look for unexpected proxy configuration or changes to outbound routing from payment services.
Review payment API logs for unusual responses, refunds, order-state changes or reconciliation mismatches.
Investigate anomalous access to merchant credentials, signing material or transaction data.
Check deployed dependency inventories and build manifests for use of the affected library.
Mitigation and prioritisation
Upgrade to the fixed release or later; verify the resolved dependency is present in deployed builds.
Until upgraded, block untrusted egress paths and use a trusted, tightly controlled network or proxy.
Rotate exposed credentials and signing secrets if interception is suspected; reconcile potentially affected transactions.
Test payment, refund and order-query flows in staging, then deploy through normal change controls with post-release monitoring.
A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.
If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
