Skip to content
Gopay Issues 540

Gopay Issues 540

github.com • October 4, 2026

Two critical security issues affect all 7 payment methods (微信、支付宝、通联支付、拉卡拉、PayPal、Apple、QQ) in this SDK:

CWE-295 : The shared HTTP client pkg/xhttp/client.go globally disables TLS certificate verification:

Every payment API call — Pay() , Refund() , Query() — transmits credentials and transaction data over a connection that silently accepts any self-signed or invalid certificate.

CWE-798 : A complete RSA 2048-bit private key, merchant ID (CusId), and AppId are hardcoded in allinpay/cert/cert.go and committed to the public repository:

All payment methods use xhttp.NewClient() :

allinpay/client.go (通联支付)

wechat/client.go (微信支付)

alipay/client.go (支付宝)

lakala/client.go (拉卡拉)

Or remove the explicit TLSClientConfig to use Go's secure defaults.

For CWE-798 (cert.go):

Revoke the exposed RSA keypair if it is a real production credential

Remove PrivateKey from source code

Use environment variables or a config file excluded from git

Add the certificate file to .gitignore

Full technical report available on request.