Two critical security issues affect all 7 payment methods (微信、支付宝、通联支付、拉卡拉、PayPal、Apple、QQ) in this SDK:
CWE-295 : The shared HTTP client pkg/xhttp/client.go globally disables TLS certificate verification:
Every payment API call — Pay() , Refund() , Query() — transmits credentials and transaction data over a connection that silently accepts any self-signed or invalid certificate.
CWE-798 : A complete RSA 2048-bit private key, merchant ID (CusId), and AppId are hardcoded in allinpay/cert/cert.go and committed to the public repository:
All payment methods use xhttp.NewClient() :
allinpay/client.go (通联支付)
wechat/client.go (微信支付)
alipay/client.go (支付宝)
lakala/client.go (拉卡拉)
Or remove the explicit TLSClientConfig to use Go's secure defaults.
For CWE-798 (cert.go):
Revoke the exposed RSA keypair if it is a real production credential
Remove PrivateKey from source code
Use environment variables or a config file excluded from git
Add the certificate file to .gitignore
Full technical report available on request.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
